Last seven days
- First activity
- Aug 7, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
TELEPUZ is a modular Windows remote-access malware family active since at least late April 2026 and commonly delivered through ClickFix social-engineering chains.
Profile source: Mallory opens in a new tabTELEPUZ
TELEPUZ is a modular Windows remote-access malware family active since at least late April 2026 and commonly delivered through ClickFix social-engineering chains. Victims are lured into manually executing a malicious command from a fake verification or troubleshooting page, after which a VIDAR stage retrieves a TELEPUZ stager and the main payload. TELEPUZ appears to be under active development and has been assessed as a likely malware-as-a-service offering, although no specific operator has been confirmed.
The malware is designed to remain lightweight at first and extend functionality through additional modules. Core capabilities include remote command execution, file and process operations, screenshot capture, host reconnaissance, and data upload. Downloaded modules add keylogging, browser cookie extraction, credential and data theft, and web-injection functionality. Its web-injection component interacts with Chromium-based browsers and Firefox through browser debugging interfaces rather than traditional browser hooking, and observed rule sets indicate an emphasis on financial fraud by altering payment-related form fields.
TELEPUZ incorporates extensive anti-analysis and defense-evasion measures. Reported behaviors include anti-virtual-machine and anti-debugging checks, geofencing to avoid systems configured for certain CIS-region locales, string encryption, dynamic API resolution, indirect system calls, unhooking of NTDLL, patching of AMSI and ETW-related functions, and removal of third-party DLL notification callbacks. It can relaunch itself through trusted Windows utilities, validate execution context, and terminate or stall when sandboxing or debugging is detected.
For persistence and privilege gain, TELEPUZ can copy itself into persistent locations, bypass User Account Control, steal higher-privileged tokens, and register itself as a Windows service. Command-and-control communications use a WebSocket-based JSON protocol. If primary infrastructure is unavailable, TELEPUZ can recover encrypted fallback command-and-control information through multiple dead-drop style channels, including Telegram, Steam profile metadata, DNS, and a Polygon blockchain smart contract; the blockchain mechanism has also been used as a kill-switch condition.
TELEPUZ targets Windows systems and should be treated as a full-compromise malware family because it combines durable access, credential and session theft, browser manipulation, and secondary payload delivery within a single modular framework.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Reporting
A ClickFix social-engineering campaign is tricking Windows users into copying and executing malicious commands from fake verification pages, leading to infection with the modular TELEPUZ remote-access trojan. Researchers said the intrusion chain uses a VIDAR-based second stage to retrieve a TELEPUZ loader and payload, after which the malware establishes command-and-control over WebSockets using a JSON-based protocol and exposes 36 remote commands to operators. TELEPUZ is designed to begin as a lightweight foothold and then pull down additional modules for credential theft, keylogging, browser cookie extraction, web injection, and further payload delivery. The malware also uses anti-analysis techniques, UAC bypass, token theft, and Windows service persistence, while maintaining fallback methods for recovering C2 details through Telegram, a Steam profile, DNS records, and a Polygon smart contract; defenders were urged to train users not to paste commands from browser prompts, monitor PowerShell and rundll32.exe, isolate infected endpoints, and prioritize browser-session and credential remediation.
Security researchers report that ClickFix has become a major initial-access technique, relying on social engineering rather than software exploits to trick users into pasting attacker-provided commands into Windows Run or macOS Terminal. ESET said detections rose 108% from H2 2025 to H1 2026, while RH-ISAC described a broader 517% increase from late 2024 into the first half of 2025 and noted that Microsoft saw the method in 47% of initial-access cases handled by Defender Experts. Attackers have expanded ClickFix beyond Windows to macOS, delivered it through compromised WordPress sites, and improved lures with fake BSOD screens, frozen document viewers, and service-specific error messages. The technique is now used by both cybercriminals and state-backed groups, with RH-ISAC linking adoption to Sandworm, APT28, MuddyWater, and Kimsuky and citing Sandworm activity against organizations in Ukraine, including at least one compromise involving FreakyPoll malware. Researchers also observed ClickFix delivering malware such as ACR Stealer, OkoBot, TELEPUZ, ClickLock Stealer, and DriveSurge, while newer variants including CrashFix, FileFix, PromptFix, and ConsentFix show continued evolution. ESET additionally identified an "AI-fix" variant that abuses legitimate domains tied to Anthropic Artifact, OpenAI Canvas, and Microsoft Copilot Pages to display fake troubleshooting content for nonexistent AI problems, underscoring how attackers are blending trusted platforms, AI branding, and increasingly industrialized delivery infrastructure.
CERT-UA reported that the Russia-linked Sandworm cluster UAC-0145, tied to UAC-0002 and also tracked as APT44 and Seashell Blizzard, has run a sustained campaign against Ukrainian targets using several social-engineering and malware-delivery methods. Investigators said attackers compromised more than 10 websites and deployed ClickFix-style fake CAPTCHA pages that instructed visitors to paste malicious PowerShell commands into Windows, while other lures included trojanized software installers from torrent trackers, bogus antivirus installation requests sent through Signal, and a fake Android security app. CERT-UA linked the activity to long-running operations targeting Ukrainian government and military-related organizations. The campaign used a broad malware ecosystem including GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, SMARTAXE, and the Android backdoor COWARDDUCK, alongside legitimate tools such as OpenSSH, Tor, and rsync for persistence, tunneling, and exfiltration. CERT-UA said at least one infection delivered through a trojanized installer enabled persistence and lateral movement inside an organization and was later used in a destructive attack against the infrastructure of a central executive authority of Ukraine. Analysts also found the operators using Cloaking.House and blockchain eth_call lookups to retrieve remote domains dynamically, while the Android malware was capable of stealing files, contacts, device data, and real-time geolocation and used the Dropbox API and content from legitimate services in its command-and-control workflow.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.