A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves.
The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators.
The attack begins with a fake verification-style page that asks a visitor to copy and execute a command.
That action downloads a VIDAR-based second stage, which then retrieves the TELEPUZ loader and its main payload, continuing a familiar pattern seen in recent ClickFix malware campaigns that turn user actions into initial access.
Elastic said in a report shared with Cyber Security News (CSN) that TELEPUZ has been active since late April 2026 and appears to be developing quickly.
Researchers observed regular uploads of new builds and a sharp increase in activity from early June, suggesting the operation is expanding.
.webp)
The malware is designed to stay small at first, then download extra features when needed. That approach lets operators add information-stealing, keystroke logging, browser manipulation, and other functions without placing every capability in the initial file.
ClickFix Campaign Delivers Modular TELEPUZ Malware
TELEPUZ communicates with its command-and-control server through WebSockets, using a JSON-based protocol to exchange information and receive tasks.
It can repeatedly try its main server, then seek replacement infrastructure through Telegram, a Steam profile, DNS records, or a Polygon blockchain smart contract if contact fails.
The 36 available commands give attackers broad control over an infected device. They include options to run commands, list files and processes, take screenshots, upload data, create ZIP archives, delete files, change the beacon interval, update the malware, and terminate jobs.
.webp)
Several commands are built for credential theft and follow-on intrusion. TELEPUZ can retrieve a stealer module, start a keylogger, extract Chromium browser cookies, download other malware modules, and run executable files inside hollowed processes, placing it alongside threats that target browser credentials and cookies.
The malware also includes a web-injection module that can interact with Chromium-based browsers and Firefox.
Rather than relying solely on traditional browser code injection, the component can use browser debugging interfaces to intercept pages, execute JavaScript, manage rules, and potentially alter financial form fields.
Evasion and Defensive Steps
Before beginning normal activity, TELEPUZ checks whether it is running in a virtual machine, sandbox, debugger, or an excluded geographic region.
It also uses encrypted strings, dynamic API lookups, indirect system calls, and patches designed to weaken Windows antimalware scanning and event tracing.
For persistence, the malware can copy itself from temporary folders, relaunch through rundll32.exe, bypass User Account Control, steal higher-privileged access tokens, and register a Windows service.
These steps can make a simple ClickFix mistake become a lasting compromise that is harder to investigate.
.webp)
Organizations should train users never to paste commands from browser prompts into Run, Command Prompt, or PowerShell windows.
Teams should also monitor unusual PowerShell and rundll32.exe activity, block listed indicators, use DNS and web filtering, and isolate suspected endpoints quickly, measures also recommended in coverage of multi-stage Vidar delivery.
Security teams should treat browser-session theft as a priority after a confirmed infection.
Reset exposed passwords, revoke active sessions, rotate privileged credentials, and review browser data, while endpoint monitoring should look for unusual module downloads and outbound WebSocket traffic, similar to activity described in WebSocket-enabled malware operations.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps://memshowblob[.]forum/api/index.php?a=grab |
ClickFix-delivered second-stage download URL |
| SHA-256 | 580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954 |
VIDAR Go variant |
| SHA-256 | 03fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746 |
TELEPUZ stager |
| Domain | hurgadatour[.]shop |
TELEPUZ stager and payload hosting domain |
| File name | install.exe |
TELEPUZ stager |
| File name | telepuz.dll |
TELEPUZ main payload |
| Domain | chubrik[.]sbs |
Staging domain |
| URL | hxxps://chubrik[.]sbs/files/xK7mR9pL2nQw5tY8ygvfuyze.dll |
Third-stage payload URL |
| Domain | betalegenda[.]cfd |
Staging domain |
| URL | hxxps://betalegenda[.]cfd/files/xK7mR9pL2nQw5tY8kmwvogwx.dll |
Third-stage payload URL |
| Domain | mavpaprokla[.]lat |
Staging domain |
| URL | hxxps://mavpaprokla[.]lat/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | comicstar[.]lat |
Staging domain |
| URL | hxxps://comicstar[.]lat/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | bigblower[.]click |
Staging domain |
| URL | hxxps://bigblower[.]click/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | momasites[.]lol |
Staging domain |
| URL | hxxps://momasites[.]lol/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | momasites[.]com |
Staging domain |
| URL | hxxps://momasites[.]com/files/telemetrywork/telepuz |
Third-stage payload URL |
| Domain | mamsites[.]lol |
Staging domain |
| URL | hxxps://mamsites[.]lol/files/telemetrywork/telepuz.dll |
Third-stage payload URL |
| Domain | hardenedom[.]shop |
Staging domain |
| URL | hxxps://hardenedom[.]shop/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | hardendedom[.]shop |
Staging domain |
| URL | hxxps://hardendedom[.]shop/files/lemetriawork/epuz.dll |
Third-stage payload URL |
| Domain | hardendom[.]shop |
Staging domain |
| URL | hxxps://hardendom[.]shop/files/telemetry/telepuz.dll |
Third-stage payload URL |
| Domain | hardeneddom[.]shop |
Staging domain |
| URL | hxxps://hardeneddom[.]shop/files/telemetrywork/telepuz |
Third-stage payload URL |
| Domain | netblokirovka[.]asia |
Staging domain |
| URL | hxxps://netblokirovka[.]asia/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | netblokir[.]asia |
Staging domain |
| URL | hxxps://netblokir[.]asia/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | netlobikrovka[.]asia |
Staging domain |
| URL | hxxps://netlobikrovka[.]asia/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | neblokirovka[.]as |
Staging domain |
| URL | hxxps://neblokirovka[.]as/telemetrynetwork/telepuz.dll |
Third-stage payload URL |
| Domain | kidsko[.]shop |
Staging domain |
| URL | hxxps://kidsko[.]shop/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | mazaporka[.]shop |
Staging domain |
| URL | hxxps://mazaporka[.]shop/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| IP address | 172.67.215.214 |
Staging infrastructure IP |
| URL | hxxps://172.67.215.214/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | krabsburger[.]xyz |
Staging domain |
| URL | hxxp://krabsburger[.]xyz/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | zewaplus[.]club |
Payload hosting domain |
| URL | hxxps://zewaplus[.]club/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| IP address | 172.67.165.144 |
Staging infrastructure IP |
| URL | hxxps://172.67.165.144/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | cal.joycedoula[.]com[.]br |
Primary TELEPUZ command-and-control domain |
| Domain | cal.snehamumbai[.]org |
Fallback command-and-control domain |
| Telegram | t[.]me/chanadarkpart |
Telegram fallback C2 retrieval channel |
| URL | hxxps://steamcommunity[.]com/profiles/76561199705801219 |
Steam profile used for fallback C2 retrieval |
| Domain | codebasecode[.]com |
DNS-based fallback C2 lookup domain |
| Blockchain address | 0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753E |
Polygon smart contract used for fallback C2 retrieval |
| SHA-256 | 58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed |
Reference TELEPUZ main payload |
| SHA-256 | bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343 |
TELEPUZ main payload |
| SHA-256 | ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e |
TELEPUZ main payload |
| SHA-256 | a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3 |
TELEPUZ keylogger module |
| SHA-256 | 9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477eb |
TELEPUZ stealer module |
| SHA-256 | 444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1 |
TELEPUZ web-injector module |
| Mutex | cfgmgrmtx |
TELEPUZ mutex |
| Mutex | bginfodmtx |
TELEPUZ mutex |
| Mutex | wfj64mtx |
TELEPUZ mutex |
| File name | AppData.dll |
TELEPUZ persistence artifact |
| File name | ProgramData.dll |
TELEPUZ installation artifact |
| File name | agent.dll |
TELEPUZ installation artifact |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands appeared first on Cyber Security News.
