logo

TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details

ID: a38465d3-ae90-5fa6-a5cf-5c58d41c8be1

STIX ID: report--a38465d3-ae90-5fa6-a5cf-5c58d41c8be1

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Mayura Kathir

...
...

TELEPUZ is a modular, stealthy 64‑bit DLL malware observed being distributed through a ClickFix social engineering → VIDAR chain; it uses advanced evasion (garbage instructions, custom RC4 string encryption, import hashing, mapped ntdll/syscall trampolines), disables AMSI/ETW, achieves persistence as a service, and includes a powerful WebInjector module that manipulates browser debugging interfaces to intercept and alter financial transactions. The report documents active infrastructure and many IOCs (domains, IPs, VirusTotal submissions), fallback C2 mechanisms (Telegram/Steam/blockchain), and signs of a potentially MaaS-style, rapidly evolving campaign posing a significant financial fraud and credential-theft risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.