TELEPUZ is a modular Windows remote-access malware family active since at least late April 2026 and commonly delivered through ClickFix social-engineering chains. Victims are lured into manually executing a malicious command from a fake verification or troubleshooting page, after which a VIDAR stage retrieves a TELEPUZ stager and the main payload. TELEPUZ appears to be under active development and has been assessed as a likely malware-as-a-service offering, although no specific operator has been confirmed.
The malware is designed to remain lightweight at first and extend functionality through additional modules. Core capabilities include remote command execution, file and process operations, screenshot capture, host reconnaissance, and data upload. Downloaded modules add keylogging, browser cookie extraction, credential and data theft, and web-injection functionality. Its web-injection component interacts with Chromium-based browsers and Firefox through browser debugging interfaces rather than traditional browser hooking, and observed rule sets indicate an emphasis on financial fraud by altering payment-related form fields.
TELEPUZ incorporates extensive anti-analysis and defense-evasion measures. Reported behaviors include anti-virtual-machine and anti-debugging checks, geofencing to avoid systems configured for certain CIS-region locales, string encryption, dynamic API resolution, indirect system calls, unhooking of NTDLL, patching of AMSI and ETW-related functions, and removal of third-party DLL notification callbacks. It can relaunch itself through trusted Windows utilities, validate execution context, and terminate or stall when sandboxing or debugging is detected.
For persistence and privilege gain, TELEPUZ can copy itself into persistent locations, bypass User Account Control, steal higher-privileged tokens, and register itself as a Windows service. Command-and-control communications use a WebSocket-based JSON protocol. If primary infrastructure is unavailable, TELEPUZ can recover encrypted fallback command-and-control information through multiple dead-drop style channels, including Telegram, Steam profile metadata, DNS, and a Polygon blockchain smart contract; the blockchain mechanism has also been used as a kill-switch condition.
TELEPUZ targets Windows systems and should be treated as a full-compromise malware family because it combines durable access, credential and session theft, browser manipulation, and secondary payload delivery within a single modular framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
From there, operators can pick from 36 commands. Those cover screenshots, file upload, process listing, and shellcode injection.
The malware pulls its features down as separate modules... Meanwhile, separate downloaded modules handle keylogging, stealing, browser cookie theft, and web injection.
For persistence, the malware can copy itself from temporary folders, relaunch through rundll32.exe, bypass User Account Control, steal higher-privileged access tokens...
Then it elevates privileges through a UAC bypass and registers itself as a Windows service under a harmless-looking name.
For persistence, the malware can copy itself from temporary folders, relaunch through rundll32.exe... and register a Windows service.
It also uses encrypted strings, dynamic API lookups, indirect system calls...
Should the checks pass, the malware unhooks NTDLL, patches AMSI and ETW, and strips third-party DLL notification callbacks.
It also uses encrypted strings, dynamic API lookups, indirect system calls...
Each holds an encrypted address that operators can rotate at will.
They include options to run commands, list files and processes, take screenshots, upload data, create ZIP archives, delete files...
For persistence, the malware can copy itself from temporary folders, relaunch through rundll32.exe, bypass User Account Control, steal higher-privileged access tokens...
For persistence, the malware can copy itself from temporary folders, relaunch through rundll32.exe...
Before beginning normal activity, TELEPUZ checks whether it is running in a virtual machine, sandbox, debugger, or an excluded geographic region.
From there, operators can pick from 36 commands. Those cover screenshots, file upload, process listing, and shellcode injection.
It beacons hostname, username, OS version, and architecture.
It can repeatedly try its main server, then seek replacement infrastructure through Telegram, a Steam profile, DNS records, or a Polygon blockchain smart contract if contact fails.
Once connected, TELEPUZ speaks a simple JSON protocol over WebSockets. It beacons hostname, username, OS version, and architecture.
Once connected, TELEPUZ speaks a simple JSON protocol over WebSockets.
Running that command fetches the second stage into the temporary folder. In this campaign, VIDAR pulls down two more pieces: a small stager and the main TELEPUZ library.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular Windows malware family delivered via ClickFix social engineering and a VIDAR loader. It uses WebSocket C2, supports 36 commands, performs anti-VM/anti-debugging checks, unhooks NTDLL, patches AMSI and ETW, uses a UAC bypass for privilege escalation, persists as a Windows service, and downloads modules for keylogging, credential/data theft, browser cookie theft, and web injection aimed at payment-field manipulation such as IBAN swapping.
A modular remote-access malware delivered via ClickFix social engineering. It uses WebSockets and a JSON-based protocol for C2, supports 36 remote commands, can download additional modules for credential theft, keylogging, browser cookie extraction, web injection, process hollowing, persistence, UAC bypass, token theft, and anti-analysis/evasion.
TELEPUZ is a modular remote-access malware delivered via ClickFix lures. It uses WebSockets and a JSON-based protocol for C2, supports fallback C2 retrieval via Telegram, Steam, DNS, and a Polygon smart contract, and can execute commands, manage files/processes, take screenshots, upload data, deploy additional modules, steal browser cookies, run a keylogger, and perform web injection against Chromium-based browsers and Firefox. It also includes anti-analysis, UAC bypass, token theft, and Windows service persistence features.
Named as another malware family distributed via ClickFix in the broader threat landscape.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.