A newly identified malware family named TELEPUZ is being distributed through ClickFix social engineering campaigns that trick users into manually executing malicious PowerShell commands disguised as browser fixes, software updates, or CAPTCHA verification steps. The attack relies on clipboard hijacking (pastejacking) rather than software vulnerabilities, leading to the installation of TELEPUZ, a modular malware capable of credential theft, browser manipulation, remote command execution, persistence, and the deployment of additional payloads. The malware incorporates advanced defense evasion, anti-analysis, and privilege escalation techniques while maintaining resilient command-and-control (C2) communications through multiple fallback mechanisms. Organizations should reinforce user awareness, restrict unauthorized PowerShell execution, and deploy endpoint security solutions capable of detecting this attack chain.
The TELEPUZ attack begins when users are tricked into executing malicious PowerShell commands through ClickFix social engineering prompts displayed on compromised websites. These prompts, disguised as browser fixes or CAPTCHA verification steps, use clipboard hijacking (pastejacking) to copy malicious commands to the victim's clipboard. Once executed, the PowerShell command downloads a Go-based variant of the Vidar Stealer, which harvests sensitive information and retrieves a second-stage stager that downloads and launches TELEPUZ using the legitimate Windows utility rundll32.exe.
Before activating its payload, TELEPUZ performs extensive anti-analysis and geolocation checks to detect virtual machines, sandboxes, and systems located in Commonwealth of Independent States (CIS) countries. It then disables security mechanisms by unhooking NTDLL, bypassing AMSI, and disabling ETW, before attempting privilege escalation and establishing persistence as a Windows service. The malware communicates with its command-and-control (C2) server over encrypted WebSocket connections and supports multiple fallback C2 retrieval methods through Telegram, Steam Community profiles, DNS records, and Polygon blockchain smart contracts. These capabilities enable remote command execution, credential theft, browser manipulation, and the deployment of additional malware. The details and technicalities of the attack campaign are discussed further below.
Delivery and Infection Chain:
The TELEPUZ campaign is delivered through ClickFix social engineering attacks hosted on compromised or malicious websites that display fake browser errors, software update prompts, or CAPTCHA verification messages. These pages use clipboard hijacking (pastejacking) to automatically copy a malicious PowerShell command to the user's clipboard and instruct them to paste and execute it manually. Once executed, the command initiates a multi-stage infection process that ultimately installs TELEPUZ, establishes persistence, and provides attackers with remote access to the compromised system.
The infection chain was identified as follows:
Technical Capabilities:
TELEPUZ incorporates numerous capabilities that enable stealth, persistence, and remote administration of compromised systems. The malware employs advanced defense evasion techniques, including AMSI bypass, ETW disablement, NTDLL unhooking, indirect system calls, import hashing, and string encryption to hinder detection and analysis. It performs anti-virtual machine (anti-VM), sandbox, hardware, and geolocation checks before attempting privilege escalation using COM elevation and SYSTEM token theft. TELEPUZ establishes persistence as a Windows service and supports extensive post-compromise capabilities, including command execution, file operations, process management, keylogging, screenshot capture, browser cookie theft, web injection, and the deployment of additional executables or DLL modules through encrypted WebSocket communications.
Attribution and Evolution:
According to current analysis, TELEPUZ is likely being developed by a single developer or a small team with significant malware development experience. Its modular architecture, regular updates, and the continuous emergence of new samples suggest that it is being distributed under a Malware-as-a-Service (MaaS) model. The campaign also demonstrates the continued evolution of ClickFix as an initial access technique by combining convincing social engineering with sophisticated malware capable of bypassing modern security controls. Furthermore, the use of multiple fallback C2 mechanisms reflects an increasing emphasis on resilient and difficult-to-disrupt attacker infrastructure.
Active Campaign and Geographic Spread:
Since late April 2026, the TELEPUZ campaign has been actively targeting users worldwide. Although no specific industry has been identified as the primary target, the malware intentionally avoids execution on systems located within Commonwealth of Independent States (CIS) countries. While known C2 servers have been hosted on compromised websites in Brazil and India, the staging infrastructure is protected by Cloudflare. The campaign remains active and continues to evolve, as evidenced by the steady emergence of newly identified malware samples.
Conclusion:
TELEPUZ represents a sophisticated malware threat that combines advanced defense evasion techniques with the increasingly prevalent ClickFix social engineering method. By relying on user interaction rather than software vulnerabilities, the campaign effectively bypasses many traditional security measures while establishing persistent and privileged access to compromised systems. Organizations should strengthen user awareness of ClickFix attacks, restrict unauthorized PowerShell execution, deploy behavior-based Endpoint Detection and Response (EDR) solutions, and continuously monitor for suspicious PowerShell activity, rundll32.exe execution, Windows service creation, and outbound WebSocket communications associated with this threat.
Successful infection with TELEPUZ can result in the theft of credentials, browser cookies, and other sensitive information, enabling attackers to hijack authenticated sessions and gain unauthorized access to enterprise resources. The malware also provides remote command execution, file manipulation, browser injection, screenshot capture, and keylogging capabilities while establishing persistence with elevated privileges. These capabilities allow attackers to deploy additional malware, move laterally across networks, exfiltrate sensitive data, and maintain long-term access to compromised environments, significantly increasing the risk of enterprise-wide compromise.
https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix