logo

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

ID: c6fc8aa8-8eca-5878-a3d0-eee153520683

STIX ID: report--c6fc8aa8-8eca-5878-a3d0-eee153520683

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**TELEPUZ** is a lightweight, modular C-based infostealer first observed in April 2026 and distributed via ClickFix/pastejacking; a Go Vidar stealer variant acts as a second-stage to deploy a stager that loads telepuz.dll. The report documents delivery and persistence mechanisms (COM elevation moniker, service registration, token theft to reach SYSTEM), extensive defense evasion (anti-VM, import hashing, string encryption, AMSI/ETW unhooking), broad capabilities (file and process management, keystroke logging, browser cookie theft and web injection via CDP/WebDriver BiDi), WebSocket/TLS C2 with multiple fallback retrieval methods (Telegram, Steam profile, DNS, Polygon smart contract), and indicators including staging/C2 domains and a Telegram channel—signs point to active development and probable malware-as-a-service distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.