ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves.

The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators.

The attack begins with a fake verification-style page that asks a visitor to copy and execute a command.

That action downloads a VIDAR-based second stage, which then retrieves the TELEPUZ loader and its main payload, continuing a familiar pattern seen in recent ClickFix malware campaigns that turn user actions into initial access.

Elastic said in a report shared with Cyber Security News (CSN) that TELEPUZ has been active since late April 2026 and appears to be developing quickly.

Researchers observed regular uploads of new builds and a sharp increase in activity from early June, suggesting the operation is expanding.

TELEPUZ infection chain (Source - Elastic)
TELEPUZ infection chain (Source – Elastic)

The malware is designed to stay small at first, then download extra features when needed. That approach lets operators add information-stealing, keystroke logging, browser manipulation, and other functions without placing every capability in the initial file.

ClickFix Campaign Delivers Modular TELEPUZ Malware

TELEPUZ communicates with its command-and-control server through WebSockets, using a JSON-based protocol to exchange information and receive tasks.

It can repeatedly try its main server, then seek replacement infrastructure through Telegram, a Steam profile, DNS records, or a Polygon blockchain smart contract if contact fails.

The 36 available commands give attackers broad control over an infected device. They include options to run commands, list files and processes, take screenshots, upload data, create ZIP archives, delete files, change the beacon interval, update the malware, and terminate jobs.

TELEPUZ DownloadRunModule function downloading DLL (Source - Elastic)
TELEPUZ DownloadRunModule function downloading DLL (Source – Elastic)

Several commands are built for credential theft and follow-on intrusion. TELEPUZ can retrieve a stealer module, start a keylogger, extract Chromium browser cookies, download other malware modules, and run executable files inside hollowed processes, placing it alongside threats that target browser credentials and cookies.

The malware also includes a web-injection module that can interact with Chromium-based browsers and Firefox.

Rather than relying solely on traditional browser code injection, the component can use browser debugging interfaces to intercept pages, execute JavaScript, manage rules, and potentially alter financial form fields.

Evasion and Defensive Steps

Before beginning normal activity, TELEPUZ checks whether it is running in a virtual machine, sandbox, debugger, or an excluded geographic region.

It also uses encrypted strings, dynamic API lookups, indirect system calls, and patches designed to weaken Windows antimalware scanning and event tracing.

For persistence, the malware can copy itself from temporary folders, relaunch through rundll32.exe, bypass User Account Control, steal higher-privileged access tokens, and register a Windows service.

These steps can make a simple ClickFix mistake become a lasting compromise that is harder to investigate.

TELEPUZ code showing ROR bit rotation operations (Source - Elastic)
TELEPUZ code showing ROR bit rotation operations (Source – Elastic)

Organizations should train users never to paste commands from browser prompts into Run, Command Prompt, or PowerShell windows.

Teams should also monitor unusual PowerShell and rundll32.exe activity, block listed indicators, use DNS and web filtering, and isolate suspected endpoints quickly, measures also recommended in coverage of multi-stage Vidar delivery.

Security teams should treat browser-session theft as a priority after a confirmed infection.

Reset exposed passwords, revoke active sessions, rotate privileged credentials, and review browser data, while endpoint monitoring should look for unusual module downloads and outbound WebSocket traffic, similar to activity described in WebSocket-enabled malware operations.

Indicators of compromise (IoCs):-

Type Indicator Description
URL hxxps://memshowblob[.]forum/api/index.php?a=grab ClickFix-delivered second-stage download URL
SHA-256 580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954 VIDAR Go variant
SHA-256 03fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746 TELEPUZ stager
Domain hurgadatour[.]shop TELEPUZ stager and payload hosting domain
File name install.exe TELEPUZ stager
File name telepuz.dll TELEPUZ main payload
Domain chubrik[.]sbs Staging domain
URL hxxps://chubrik[.]sbs/files/xK7mR9pL2nQw5tY8ygvfuyze.dll Third-stage payload URL
Domain betalegenda[.]cfd Staging domain
URL hxxps://betalegenda[.]cfd/files/xK7mR9pL2nQw5tY8kmwvogwx.dll Third-stage payload URL
Domain mavpaprokla[.]lat Staging domain
URL hxxps://mavpaprokla[.]lat/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain comicstar[.]lat Staging domain
URL hxxps://comicstar[.]lat/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain bigblower[.]click Staging domain
URL hxxps://bigblower[.]click/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain momasites[.]lol Staging domain
URL hxxps://momasites[.]lol/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain momasites[.]com Staging domain
URL hxxps://momasites[.]com/files/telemetrywork/telepuz Third-stage payload URL
Domain mamsites[.]lol Staging domain
URL hxxps://mamsites[.]lol/files/telemetrywork/telepuz.dll Third-stage payload URL
Domain hardenedom[.]shop Staging domain
URL hxxps://hardenedom[.]shop/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain hardendedom[.]shop Staging domain
URL hxxps://hardendedom[.]shop/files/lemetriawork/epuz.dll Third-stage payload URL
Domain hardendom[.]shop Staging domain
URL hxxps://hardendom[.]shop/files/telemetry/telepuz.dll Third-stage payload URL
Domain hardeneddom[.]shop Staging domain
URL hxxps://hardeneddom[.]shop/files/telemetrywork/telepuz Third-stage payload URL
Domain netblokirovka[.]asia Staging domain
URL hxxps://netblokirovka[.]asia/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain netblokir[.]asia Staging domain
URL hxxps://netblokir[.]asia/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain netlobikrovka[.]asia Staging domain
URL hxxps://netlobikrovka[.]asia/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain neblokirovka[.]as Staging domain
URL hxxps://neblokirovka[.]as/telemetrynetwork/telepuz.dll Third-stage payload URL
Domain kidsko[.]shop Staging domain
URL hxxps://kidsko[.]shop/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain mazaporka[.]shop Staging domain
URL hxxps://mazaporka[.]shop/files/telemetriawork/telepuz.dll Third-stage payload URL
IP address 172.67.215.214 Staging infrastructure IP
URL hxxps://172.67.215.214/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain krabsburger[.]xyz Staging domain
URL hxxp://krabsburger[.]xyz/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain zewaplus[.]club Payload hosting domain
URL hxxps://zewaplus[.]club/files/telemetriawork/telepuz.dll Third-stage payload URL
IP address 172.67.165.144 Staging infrastructure IP
URL hxxps://172.67.165.144/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain cal.joycedoula[.]com[.]br Primary TELEPUZ command-and-control domain
Domain cal.snehamumbai[.]org Fallback command-and-control domain
Telegram t[.]me/chanadarkpart Telegram fallback C2 retrieval channel
URL hxxps://steamcommunity[.]com/profiles/76561199705801219 Steam profile used for fallback C2 retrieval
Domain codebasecode[.]com DNS-based fallback C2 lookup domain
Blockchain address 0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753E Polygon smart contract used for fallback C2 retrieval
SHA-256 58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed Reference TELEPUZ main payload
SHA-256 bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343 TELEPUZ main payload
SHA-256 ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e TELEPUZ main payload
SHA-256 a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3 TELEPUZ keylogger module
SHA-256 9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477eb TELEPUZ stealer module
SHA-256 444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1 TELEPUZ web-injector module
Mutex cfgmgrmtx TELEPUZ mutex
Mutex bginfodmtx TELEPUZ mutex
Mutex wfj64mtx TELEPUZ mutex
File name AppData.dll TELEPUZ persistence artifact
File name ProgramData.dll TELEPUZ installation artifact
File name agent.dll TELEPUZ installation artifact

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands appeared first on Cyber Security News.