Skip to content

TELEPUZ

TELEPUZ is a modular Windows remote-access malware family active since at least late April 2026 and commonly delivered through ClickFix social-engineering chains.

Profile source: Mallory opens in a new tab

TELEPUZ

Family profile

TELEPUZ is a modular Windows remote-access malware family active since at least late April 2026 and commonly delivered through ClickFix social-engineering chains. Victims are lured into manually executing a malicious command from a fake verification or troubleshooting page, after which a VIDAR stage retrieves a TELEPUZ stager and the main payload. TELEPUZ appears to be under active development and has been assessed as a likely malware-as-a-service offering, although no specific operator has been confirmed.

The malware is designed to remain lightweight at first and extend functionality through additional modules. Core capabilities include remote command execution, file and process operations, screenshot capture, host reconnaissance, and data upload. Downloaded modules add keylogging, browser cookie extraction, credential and data theft, and web-injection functionality. Its web-injection component interacts with Chromium-based browsers and Firefox through browser debugging interfaces rather than traditional browser hooking, and observed rule sets indicate an emphasis on financial fraud by altering payment-related form fields.

TELEPUZ incorporates extensive anti-analysis and defense-evasion measures. Reported behaviors include anti-virtual-machine and anti-debugging checks, geofencing to avoid systems configured for certain CIS-region locales, string encryption, dynamic API resolution, indirect system calls, unhooking of NTDLL, patching of AMSI and ETW-related functions, and removal of third-party DLL notification callbacks. It can relaunch itself through trusted Windows utilities, validate execution context, and terminate or stall when sandboxing or debugging is detected.

For persistence and privilege gain, TELEPUZ can copy itself into persistent locations, bypass User Account Control, steal higher-privileged tokens, and register itself as a Windows service. Command-and-control communications use a WebSocket-based JSON protocol. If primary infrastructure is unavailable, TELEPUZ can recover encrypted fallback command-and-control information through multiple dead-drop style channels, including Telegram, Steam profile metadata, DNS, and a Polygon blockchain smart contract; the blockchain mechanism has also been used as a kill-switch condition.

TELEPUZ targets Windows systems and should be treated as a full-compromise malware family because it combines durable access, credential and session theft, browser manipulation, and secondary payload delivery within a single modular framework.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 7, 2026
Last activity
Aug 7, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

MITRE ATT&CK

TELEPUZ in ATT&CK

62 distinct techniques

Techniques

62 techniques
T1027.013 Encrypted/Encoded File T1129 Shared Modules T1548.002 Bypass User Account Control T1113 Screen Capture T1082 System Information Discovery T1057 Process Discovery T1568 Dynamic Resolution T1059 Command and Scripting Interpreter T1204 User Execution T1071.001 Web Protocols T1027.005 Indicator Removal from Tools T1071 Application Layer Protocol T1543.003 Windows Service T1056.001 Keylogging T1105 Ingress Tool Transfer T1497.001 System Checks T1539 Steal Web Session Cookie T1070 Indicator Removal T1027.007 Dynamic API Resolution T1027 Obfuscated Files or Information T1218.011 Rundll32 T1562 Impair Defenses T1185 Browser Session Hijacking T1574 Hijack Execution Flow T1134 Access Token Manipulation T1547 Boot or Logon Autostart Execution T1497 Virtualization/Sandbox Evasion T1055 Process Injection T1219 Remote Access Tools T1548 Abuse Elevation Control Mechanism T1008 Fallback Channels T1056 Input Capture T1560 Archive Collected Data T1083 File and Directory Discovery T1204.002 Malicious File T1071.004 DNS T1622 Debugger Evasion T1070.004 File Deletion T1036 Masquerading T1059.001 PowerShell T1056.003 Web Portal Capture T1059.007 JavaScript T1134.001 Token Impersonation/Theft T1115 Clipboard Data T1562.006 Indicator Blocking T1497.003 Time Based Checks T1106 Native API T1573.002 Asymmetric Cryptography T1620 Reflective Code Loading T1555 Credentials from Password Stores T1033 System Owner/User Discovery T1036.005 Match Legitimate Resource Name or Location T1518 Software Discovery T1569.002 Service Execution T1102.001 Dead Drop Resolver T1041 Exfiltration Over C2 Channel T1614.001 System Language Discovery T1566 Phishing T1560.001 Archive via Utility T1055.012 Process Hollowing T1112 Modify Registry T1134.002 Create Process with Token

Reporting

Research mentioning TELEPUZ

Jul 21
Security Online Info

TELEPUZ Malware Spreads via ClickFix Attack Chain

A ClickFix social-engineering campaign is tricking Windows users into copying and executing malicious commands from fake verification pages, leading to infection with the modular TELEPUZ remote-access trojan. Researchers said the intrusion chain uses a VIDAR-based second stage to retrieve a TELEPUZ loader and payload, after which the malware establishes command-and-control over WebSockets using a JSON-based protocol and exposes 36 remote commands to operators. TELEPUZ is designed to begin as a lightweight foothold and then pull down additional modules for credential theft, keylogging, browser cookie extraction, web injection, and further payload delivery. The malware also uses anti-analysis techniques, UAC bypass, token theft, and Windows service persistence, while maintaining fallback methods for recovering C2 details through Telegram, a Steam profile, DNS records, and a Polygon smart contract; defenders were urged to train users not to paste commands from browser prompts, monitor PowerShell and rundll32.exe, isolate infected endpoints, and prioritize browser-session and credential remediation.

Jul 20
Cyber Security News

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

Jul 20
Cryptika

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands | Cryptika Cybersecurity

Jul 20
Cyberveille

ClickFix : un invariant comportemental universel pour remplacer 50 règles de détection | CyberVeille

Security researchers report that ClickFix has become a major initial-access technique, relying on social engineering rather than software exploits to trick users into pasting attacker-provided commands into Windows Run or macOS Terminal. ESET said detections rose 108% from H2 2025 to H1 2026, while RH-ISAC described a broader 517% increase from late 2024 into the first half of 2025 and noted that Microsoft saw the method in 47% of initial-access cases handled by Defender Experts. Attackers have expanded ClickFix beyond Windows to macOS, delivered it through compromised WordPress sites, and improved lures with fake BSOD screens, frozen document viewers, and service-specific error messages. The technique is now used by both cybercriminals and state-backed groups, with RH-ISAC linking adoption to Sandworm, APT28, MuddyWater, and Kimsuky and citing Sandworm activity against organizations in Ukraine, including at least one compromise involving FreakyPoll malware. Researchers also observed ClickFix delivering malware such as ACR Stealer, OkoBot, TELEPUZ, ClickLock Stealer, and DriveSurge, while newer variants including CrashFix, FileFix, PromptFix, and ConsentFix show continued evolution. ESET additionally identified an "AI-fix" variant that abuses legitimate domains tied to Anthropic Artifact, OpenAI Canvas, and Microsoft Copilot Pages to display fake troubleshooting content for nonexistent AI problems, underscoring how attackers are blending trusted platforms, AI branding, and increasingly industrialized delivery infrastructure.

Jul 19
Trojan Killer News

Sandworm ClickFix CAPTCHAs Push Malware to Ukrainian Devices

CERT-UA reported that the Russia-linked Sandworm cluster UAC-0145, tied to UAC-0002 and also tracked as APT44 and Seashell Blizzard, has run a sustained campaign against Ukrainian targets using several social-engineering and malware-delivery methods. Investigators said attackers compromised more than 10 websites and deployed ClickFix-style fake CAPTCHA pages that instructed visitors to paste malicious PowerShell commands into Windows, while other lures included trojanized software installers from torrent trackers, bogus antivirus installation requests sent through Signal, and a fake Android security app. CERT-UA linked the activity to long-running operations targeting Ukrainian government and military-related organizations. The campaign used a broad malware ecosystem including GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, SMARTAXE, and the Android backdoor COWARDDUCK, alongside legitimate tools such as OpenSSH, Tor, and rsync for persistence, tunneling, and exfiltration. CERT-UA said at least one infection delivered through a trojanized installer enabled persistence and lateral movement inside an organization and was later used in a destructive attack against the infrastructure of a central executive authority of Ukraine. Analysts also found the operators using Cloaking.House and blockchain eth_call lookups to retrieve remote domains dynamically, while the Android malware was capable of stealing files, contacts, device data, and real-time geolocation and used the Dropbox API and content from legitimate services in its command-and-control workflow.

Jul 19
The Hacker News

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Jul 17
Rhisac

RH-ISAC | Current ClickFix Threat Landscape Developments - RH-ISAC

Jul 16
Scworld

Russian hackers use fake CAPTCHA to infect Ukrainian targets | brief | SC Media

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.