Skip to content
Data Breach

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators. The attack begins with a fake verification-sty...

· Jul 20, 2026 · 6 min read · 👁 4 views
ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves.

The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators.

The attack begins with a fake verification-style page that asks a visitor to copy and execute a command.

That action downloads a VIDAR-based second stage, which then retrieves the TELEPUZ loader and its main payload, continuing a familiar pattern seen in recent ClickFix malware campaigns that turn user actions into initial access.

Elastic said in a report shared with Cyber Security News (CSN) that TELEPUZ has been active since late April 2026 and appears to be developing quickly.

Researchers observed regular uploads of new builds and a sharp increase in activity from early June, suggesting the operation is expanding.

TELEPUZ infection chain (Source - Elastic)
TELEPUZ infection chain (Source – Elastic)

The malware is designed to stay small at first, then download extra features when needed. That approach lets operators add information-stealing, keystroke logging, browser manipulation, and other functions without placing every capability in the initial file.

ClickFix Campaign Delivers Modular TELEPUZ Malware

TELEPUZ communicates with its command-and-control server through WebSockets, using a JSON-based protocol to exchange information and receive tasks.

It can repeatedly try its main server, then seek replacement infrastructure through Telegram, a Steam profile, DNS records, or a Polygon blockchain smart contract if contact fails.

The 36 available commands give attackers broad control over an infected device. They include options to run commands, list files and processes, take screenshots, upload data, create ZIP archives, delete files, change the beacon interval, update the malware, and terminate jobs.

TELEPUZ DownloadRunModule function downloading DLL (Source - Elastic)
TELEPUZ DownloadRunModule function downloading DLL (Source – Elastic)

Several commands are built for credential theft and follow-on intrusion. TELEPUZ can retrieve a stealer module, start a keylogger, extract Chromium browser cookies, download other malware modules, and run executable files inside hollowed processes, placing it alongside threats that target browser credentials and cookies.

The malware also includes a web-injection module that can interact with Chromium-based browsers and Firefox.

Rather than relying solely on traditional browser code injection, the component can use browser debugging interfaces to intercept pages, execute JavaScript, manage rules, and potentially alter financial form fields.

Evasion and Defensive Steps

Before beginning normal activity, TELEPUZ checks whether it is running in a virtual machine, sandbox, debugger, or an excluded geographic region.

It also uses encrypted strings, dynamic API lookups, indirect system calls, and patches designed to weaken Windows antimalware scanning and event tracing.

For persistence, the malware can copy itself from temporary folders, relaunch through rundll32.exe, bypass User Account Control, steal higher-privileged access tokens, and register a Windows service.

These steps can make a simple ClickFix mistake become a lasting compromise that is harder to investigate.

TELEPUZ code showing ROR bit rotation operations (Source - Elastic)
TELEPUZ code showing ROR bit rotation operations (Source – Elastic)

Organizations should train users never to paste commands from browser prompts into Run, Command Prompt, or PowerShell windows.

Teams should also monitor unusual PowerShell and rundll32.exe activity, block listed indicators, use DNS and web filtering, and isolate suspected endpoints quickly, measures also recommended in coverage of multi-stage Vidar delivery.

Security teams should treat browser-session theft as a priority after a confirmed infection.

Reset exposed passwords, revoke active sessions, rotate privileged credentials, and review browser data, while endpoint monitoring should look for unusual module downloads and outbound WebSocket traffic, similar to activity described in WebSocket-enabled malware operations.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
URLhxxps://memshowblob[.]forum/api/index.php?a=grabClickFix-delivered second-stage download URL
SHA-256580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954VIDAR Go variant
SHA-25603fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746TELEPUZ stager
Domainhurgadatour[.]shopTELEPUZ stager and payload hosting domain
File nameinstall.exeTELEPUZ stager
File nametelepuz.dllTELEPUZ main payload
Domainchubrik[.]sbsStaging domain
URLhxxps://chubrik[.]sbs/files/xK7mR9pL2nQw5tY8ygvfuyze.dllThird-stage payload URL
Domainbetalegenda[.]cfdStaging domain
URLhxxps://betalegenda[.]cfd/files/xK7mR9pL2nQw5tY8kmwvogwx.dllThird-stage payload URL
Domainmavpaprokla[.]latStaging domain
URLhxxps://mavpaprokla[.]lat/files/telemetriawork/telepuz.dllThird-stage payload URL
Domaincomicstar[.]latStaging domain
URLhxxps://comicstar[.]lat/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainbigblower[.]clickStaging domain
URLhxxps://bigblower[.]click/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainmomasites[.]lolStaging domain
URLhxxps://momasites[.]lol/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainmomasites[.]comStaging domain
URLhxxps://momasites[.]com/files/telemetrywork/telepuzThird-stage payload URL
Domainmamsites[.]lolStaging domain
URLhxxps://mamsites[.]lol/files/telemetrywork/telepuz.dllThird-stage payload URL
Domainhardenedom[.]shopStaging domain
URLhxxps://hardenedom[.]shop/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainhardendedom[.]shopStaging domain
URLhxxps://hardendedom[.]shop/files/lemetriawork/epuz.dllThird-stage payload URL
Domainhardendom[.]shopStaging domain
URLhxxps://hardendom[.]shop/files/telemetry/telepuz.dllThird-stage payload URL
Domainhardeneddom[.]shopStaging domain
URLhxxps://hardeneddom[.]shop/files/telemetrywork/telepuzThird-stage payload URL
Domainnetblokirovka[.]asiaStaging domain
URLhxxps://netblokirovka[.]asia/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainnetblokir[.]asiaStaging domain
URLhxxps://netblokir[.]asia/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainnetlobikrovka[.]asiaStaging domain
URLhxxps://netlobikrovka[.]asia/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainneblokirovka[.]asStaging domain
URLhxxps://neblokirovka[.]as/telemetrynetwork/telepuz.dllThird-stage payload URL
Domainkidsko[.]shopStaging domain
URLhxxps://kidsko[.]shop/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainmazaporka[.]shopStaging domain
URLhxxps://mazaporka[.]shop/files/telemetriawork/telepuz.dllThird-stage payload URL
IP address172.67.215.214Staging infrastructure IP
URLhxxps://172.67.215.214/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainkrabsburger[.]xyzStaging domain
URLhxxp://krabsburger[.]xyz/files/telemetriawork/telepuz.dllThird-stage payload URL
Domainzewaplus[.]clubPayload hosting domain
URLhxxps://zewaplus[.]club/files/telemetriawork/telepuz.dllThird-stage payload URL
IP address172.67.165.144Staging infrastructure IP
URLhxxps://172.67.165.144/files/telemetriawork/telepuz.dllThird-stage payload URL
Domaincal.joycedoula[.]com[.]brPrimary TELEPUZ command-and-control domain
Domaincal.snehamumbai[.]orgFallback command-and-control domain
Telegramt[.]me/chanadarkpartTelegram fallback C2 retrieval channel
URLhxxps://steamcommunity[.]com/profiles/76561199705801219Steam profile used for fallback C2 retrieval
Domaincodebasecode[.]comDNS-based fallback C2 lookup domain
Blockchain address0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753EPolygon smart contract used for fallback C2 retrieval
SHA-25658aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eedReference TELEPUZ main payload
SHA-256bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343TELEPUZ main payload
SHA-256ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3eTELEPUZ main payload
SHA-256a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3TELEPUZ keylogger module
SHA-2569733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477ebTELEPUZ stealer module
SHA-256444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1TELEPUZ web-injector module
MutexcfgmgrmtxTELEPUZ mutex
MutexbginfodmtxTELEPUZ mutex
Mutexwfj64mtxTELEPUZ mutex
File nameAppData.dllTELEPUZ persistence artifact
File nameProgramData.dllTELEPUZ installation artifact
File nameagent.dllTELEPUZ installation artifact

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you