TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
ID: 229983d8-067e-5459-bb4b-adf229ec4216
STIX ID: report--229983d8-067e-5459-bb4b-adf229ec4216
Feed Name: Elastic Security Labs
Elastic Security Labs describes TELEPUZ, an actively developed modular Windows malware family propagated via a ClickFix social-engineering page and a VIDAR second-stage; TELEPUZ uses sophisticated evasion (indirect syscalls, NTDLL unhooking, AMSI/ETW patching), multiple UAC and privilege-escalation methods, WebSocket-based C2 with fallback resolution via Telegram/Steam/DNS/Polygon smart contract, and download-on-demand modules (keylogger, stealer, web injector, Chrome cookie extractor). The report provides technical analysis, command/URI/module mappings, persistence and installation details, sample hashes, staging/C2 domains, and a YARA rule and IOCs for detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
