TELEPUZ Malware Analysis: A New Modular Malware-as-a-Service Threat

Summary:

A newly identified malware family named TELEPUZ is being distributed through ClickFix social engineering campaigns that trick users into manually executing malicious PowerShell commands disguised as browser fixes, software updates, or CAPTCHA verification steps. The attack relies on clipboard hijacking (pastejacking) rather than software vulnerabilities, leading to the installation of TELEPUZ, a modular malware capable of credential theft, browser manipulation, remote command execution, persistence, and the deployment of additional payloads. The malware incorporates advanced defense evasion, anti-analysis, and privilege escalation techniques while maintaining resilient command-and-control (C2) communications through multiple fallback mechanisms. Organizations should reinforce user awareness, restrict unauthorized PowerShell execution, and deploy endpoint security solutions capable of detecting this attack chain.

Technical Description:

The TELEPUZ attack begins when users are tricked into executing malicious PowerShell commands through ClickFix social engineering prompts displayed on compromised websites. These prompts, disguised as browser fixes or CAPTCHA verification steps, use clipboard hijacking (pastejacking) to copy malicious commands to the victim's clipboard. Once executed, the PowerShell command downloads a Go-based variant of the Vidar Stealer, which harvests sensitive information and retrieves a second-stage stager that downloads and launches TELEPUZ using the legitimate Windows utility rundll32.exe.

Before activating its payload, TELEPUZ performs extensive anti-analysis and geolocation checks to detect virtual machines, sandboxes, and systems located in Commonwealth of Independent States (CIS) countries. It then disables security mechanisms by unhooking NTDLL, bypassing AMSI, and disabling ETW, before attempting privilege escalation and establishing persistence as a Windows service. The malware communicates with its command-and-control (C2) server over encrypted WebSocket connections and supports multiple fallback C2 retrieval methods through Telegram, Steam Community profiles, DNS records, and Polygon blockchain smart contracts. These capabilities enable remote command execution, credential theft, browser manipulation, and the deployment of additional malware. The details and technicalities of the attack campaign are discussed further below.

Delivery and Infection Chain:

The TELEPUZ campaign is delivered through ClickFix social engineering attacks hosted on compromised or malicious websites that display fake browser errors, software update prompts, or CAPTCHA verification messages. These pages use clipboard hijacking (pastejacking) to automatically copy a malicious PowerShell command to the user's clipboard and instruct them to paste and execute it manually. Once executed, the command initiates a multi-stage infection process that ultimately installs TELEPUZ, establishes persistence, and provides attackers with remote access to the compromised system.

The infection chain was identified as follows:

  • The victim visits a compromised website displaying a fake browser error or CAPTCHA prompt that instructs them to execute a PowerShell command copied to their clipboard.
  • The PowerShell command downloads and executes a Go-based Vidar Stealer, which collects sensitive information and retrieves a second-stage stager.
  • The stager downloads telepuz.dll and executes it using the legitimate Windows utility rundll32.exe.
  • TELEPUZ performs anti-analysis checks, disables Windows security mechanisms, escalates privileges, and establishes persistence by installing itself as a Windows service.
  • The malware connects to its command-and-control (C2) server using encrypted WebSocket communications, enabling attackers to execute commands, steal data, manipulate browsers, and deploy additional malware.

Technical Capabilities:

TELEPUZ incorporates numerous capabilities that enable stealth, persistence, and remote administration of compromised systems. The malware employs advanced defense evasion techniques, including AMSI bypass, ETW disablement, NTDLL unhooking, indirect system calls, import hashing, and string encryption to hinder detection and analysis. It performs anti-virtual machine (anti-VM), sandbox, hardware, and geolocation checks before attempting privilege escalation using COM elevation and SYSTEM token theft. TELEPUZ establishes persistence as a Windows service and supports extensive post-compromise capabilities, including command execution, file operations, process management, keylogging, screenshot capture, browser cookie theft, web injection, and the deployment of additional executables or DLL modules through encrypted WebSocket communications.

Attribution and Evolution:

According to current analysis, TELEPUZ is likely being developed by a single developer or a small team with significant malware development experience. Its modular architecture, regular updates, and the continuous emergence of new samples suggest that it is being distributed under a Malware-as-a-Service (MaaS) model. The campaign also demonstrates the continued evolution of ClickFix as an initial access technique by combining convincing social engineering with sophisticated malware capable of bypassing modern security controls. Furthermore, the use of multiple fallback C2 mechanisms reflects an increasing emphasis on resilient and difficult-to-disrupt attacker infrastructure.

Active Campaign and Geographic Spread:

Since late April 2026, the TELEPUZ campaign has been actively targeting users worldwide. Although no specific industry has been identified as the primary target, the malware intentionally avoids execution on systems located within Commonwealth of Independent States (CIS) countries. While known C2 servers have been hosted on compromised websites in Brazil and India, the staging infrastructure is protected by Cloudflare. The campaign remains active and continues to evolve, as evidenced by the steady emergence of newly identified malware samples.

Conclusion:

TELEPUZ represents a sophisticated malware threat that combines advanced defense evasion techniques with the increasingly prevalent ClickFix social engineering method. By relying on user interaction rather than software vulnerabilities, the campaign effectively bypasses many traditional security measures while establishing persistent and privileged access to compromised systems. Organizations should strengthen user awareness of ClickFix attacks, restrict unauthorized PowerShell execution, deploy behavior-based Endpoint Detection and Response (EDR) solutions, and continuously monitor for suspicious PowerShell activity, rundll32.exe execution, Windows service creation, and outbound WebSocket communications associated with this threat.

Impact:

Successful infection with TELEPUZ can result in the theft of credentials, browser cookies, and other sensitive information, enabling attackers to hijack authenticated sessions and gain unauthorized access to enterprise resources. The malware also provides remote command execution, file manipulation, browser injection, screenshot capture, and keylogging capabilities while establishing persistence with elevated privileges. These capabilities allow attackers to deploy additional malware, move laterally across networks, exfiltrate sensitive data, and maintain long-term access to compromised environments, significantly increasing the risk of enterprise-wide compromise.

IOC and Context Details:

Topics Details
Tactic Name Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Command and Control
Technique Name PowerShell, User Execution, Rundll32, Service Installation, Token Impersonation, Browser Session Hijacking
Sub Technique Name ClickFix, Clipboard Hijacking (Pastejacking), AMSI Bypass, ETW Disablement, COM Elevation, SYSTEM Token Theft
Attack Type Malware
Targeted Applications Windows PowerShell, Rundll32.exe, Chromium-based Browsers, Mozilla Firefox, Telegram, Steam Community
Region Impacted Global
Industry Impacted Technology, Software Development, IT Services, Developers, Enterprise
IOC's Domains:
chubrik[.]sbs
betalegenda[.]cfd
mavpaprokla[.]lat
comicstar[.]lat
bigblower[.]click
momasites[.]lol
momasites[.]com
mamsites[.]lol
hardenedom[.]shop
hardendedom[.]shop
hardendom[.]shop
hardeneddom[.]shop
netblokirovka[.]asia
netblokir[.]asia
netlobikrovka[.]asia
neblokirovka[.]as
kidsko[.]shop
mazaporka[.]shop
hurgadatour[.]shop
krabsburger[.]xyz
zewaplus[.]club
cal.snehamumbai[.]org
cal.joycedoula[.]com[.]br

IP Addresses:
172.67.215[.]214
172.67.165[.]144

SHA-256 Hashes:
58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed
bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343
ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e
a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3
9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477eb
444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1

URLs:
hxxps://chubrik[.]sbs/files/xK7mR9pL2nQw5tY8/ygvfuyze.dll
hxxps://betalegenda[.]cfd/files/xK7mR9pL2nQw5tY8/kmwvogwx.dll
hxxps://mavpaprokla[.]lat/files/telemetriawork/telepuz.dll
hxxps://comicstar[.]lat/files/telemetriawork/telepuz.dll
hxxps://bigblower[.]click/files/telemetriawork/telepuz.dll
hxxps://momasites[.]lol/files/telemetriawork/telepuz.dll
hxxps://momasites[.]com/files/telemetrywork/telepuz
hxxps://mamsites[.]lol/files/telemetrywork/telepuz.dll
hxxps://hardenedom[.]shop/files/telemetriawork/telepuz.dll
hxxps://hardendedom[.]shop/files/lemetriawork/epuz.dll
hxxps://hardendom[.]shop/files/telemetry/telepuz.dll
hxxps://hardeneddom[.]shop/files/telemetrywork/telepuz
hxxps://netblokirovka[.]asia/files/telemetriawork/telepuz.dll
hxxps://netblokir[.]asia/files/telemetriawork/telepuz.dll
hxxps://netlobikrovka[.]asia/files/telemetriawork/telepuz.dll
hxxps://neblokirovka[.]as/telemetry/network/telepuz.dll
hxxps://kidsko[.]shop/files/telemetriawork/telepuz.dll
hxxps://mazaporka[.]shop/files/telemetriawork/telepuz.dll
hxxps://172.67.215[.]214/files/telemetriawork/telepuz.dll
hxxps://hurgadatour[.]shop/files/telemetriawork/telepuz.dll
hxxp://krabsburger[.]xyz/files/telemetriawork/telepuz.dll
hxxps://zewaplus[.]club/files/telemetriawork/telepuz.dll
hxxps://172.67.165[.]144/files/telemetriawork/telepuz.dll
CVE NA

Recommended Actions:

  • Educate users about ClickFix, clipboard hijacking (pastejacking), and fake CAPTCHA verification attacks.
  • Prevent users from executing untrusted PowerShell commands copied from websites.
  • Enable PowerShell Script Block Logging and Module Logging.
  • Deploy Endpoint Detection and Response (EDR) solutions capable of detecting AMSI bypass, ETW tampering, and NTDLL unhooking.
  • Monitor for abnormal execution of rundll32.exe, PowerShell, svchost.exe, and unexpected Windows service creation.
  • Block or inspect outbound WebSocket communications where operationally feasible.
  • Restrict PowerShell usage through application control policies such as Windows Defender Application Control (WDAC) or AppLocker.
  • Monitor DNS TXT queries and outbound connections to suspicious Telegram-, Steam-, or blockchain-related infrastructure used for C2 fallback.
  • Continuously update threat intelligence feeds with known TELEPUZ Indicators of Compromise (IOCs).
  • Ensure operating systems, browsers, and endpoint security solutions remain fully updated.

Reference:

https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix