Sunday, September 6, 2026

TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details

A rapidly evolving malware family dubbed TELEPUZ, a modular and lightweight threat that is gaining traction through a ClickFix–VIDAR infection chain.

Despite a relatively small command-and-control (C2) footprint, the pace of development and distribution suggests an emerging large-scale operation.

The infection begins with ClickFix social engineering, where victims are tricked into executing a malicious PowerShell command under the guise of accessing web content.

This initial stage retrieves a second-stage payload from hxxps://memshowblob[.]forum/api/index.php?a=grab, which deploys a VIDAR variant.

VIDAR then downloads TELEPUZ components, including a stager (install.exe) and the main payload (telepuz.dll), typically hosted on domains such as hurgadatour[.]shop.

The TELEPUZ payload is a 64-bit DLL written in C, designed for stealth, modularity, and efficiency. It employs multiple obfuscation techniques, including garbage instructions, custom RC4-based string encryption, and import hashing.

Additionally, it leverages indirect syscalls by mapping a clean copy of ntdll.dll and constructing syscall trampolines, effectively bypassing API hooks and endpoint detection mechanisms.

Persistence is achieved by installing the malware as a service named “CipherAllocator,” often executed via rundll32.exe within svchost.exe contexts.

TELEPUZ also performs extensive anti-analysis checks, including virtual machine detection, debugger evasion using NtQueryInformationProcess and ThreadHideFromDebugger, and geofencing to avoid execution in CIS countries.

It further disables AMSI and ETW by patching key functions such as AmsiScanBuffer and EtwEventWrite.

Elastic Security Labs Researchers said that, TELEPUZ is already exhibiting characteristics of a potential Malware-as-a-Service (MaaS) offering, with frequent updates and a growing number of samples submitted to VirusTotal.

A notable feature of TELEPUZ is its resilient C2 communication architecture. It uses WebSockets over HTTP or TLS, with endpoints like /cdn/health?sid= for beaconing.


TELEPUZ infection chain diagram showing ClickFix, PowerShell, VIDAR, install.exe stager and modular payload delivery (Source : Elastic Security Labs).
TELEPUZ infection chain diagram showing ClickFix, PowerShell, VIDAR, install.exe stager and modular payload delivery (Source : Elastic Security Labs).

If the primary C2 fails, the malware retrieves fallback infrastructure through unconventional channels, including a Telegram profile (hxxps://t[.]me/chanadarkpart), a Steam profile (https://steamcommunity.com/profiles/76561199705801219).

TELEPUZ Web Injector

DNS queries to codebasecode[.]com, and even the Polygon blockchain via JSON-RPC calls targeting smart contract 0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753E.

These fallback methods use XOR or AES-256-CBC encryption to conceal updated C2 domains such as cal.snehamumbai[.]org.

An alternative UAC bypass using AppInfo ALPC and DebugObjects. The malware first launches a non-elevated winver.exe in debug mode via RAicLaunchAdminProcess to capture its debug object handle.


TELEPUZ debugger detection checking ProcessDebugPort, ProcessDebugFlags and ThreadHideFromDebugger (Source : Elastic Security Labs).
TELEPUZ debugger detection checking ProcessDebugPort, ProcessDebugFlags and ThreadHideFromDebugger (Source : Elastic Security Labs).

Functionally, TELEPUZ supports over 30 commands, enabling file operations, process injection, privilege escalation, and module execution. Its modular design allows operators to dynamically load capabilities such as keylogging, credential stealing, and browser data extraction.

One of the most concerning components is its WebInjector module, which targets Chromium-based browsers and Firefox using Chrome DevTools Protocol (https://chromedevtools.github.io/devtools-protocol/) and WebDriver BiDi.

Unlike traditional browser injection, TELEPUZ interacts directly with browser debugging interfaces to intercept traffic and manipulate web sessions.

Telegram Biography channel t.me/chanadarkpart used by TELEPUZ for C2 fallback containing XOR-encrypted domain (Source : Elastic Security Labs).
Telegram Biography channel t.me/chanadarkpart used by TELEPUZ for C2 fallback containing XOR-encrypted domain (Source : Elastic Security Labs).

This enables attackers to steal cookies, execute arbitrary JavaScript, and modify sensitive transaction data in real time.

For example, it can replace IBAN fields during online banking sessions, effectively redirecting funds without user awareness.

The module also supports rule-based actions, including URL matching, field swapping, and response filtering, making it highly adaptable for financial fraud.

Infrastructure analysis reveals limited but strategic C2 usage, primarily through compromised legitimate domains such as cal.joycedoula[.]com[.]br and cal.snehamumbai[.]org.

Meanwhile, staging infrastructure is often protected by Cloudflare, obscuring backend hosting.

VirusTotal telemetry (e.g., https://www.virustotal.com/gui/file/58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed) shows a sharp increase in TELEPUZ sample submissions since early June 2026.

Overall, TELEPUZ represents a sophisticated and flexible threat platform combining modern evasion, modular payload delivery, and advanced browser manipulation.

Its ability to leverage legitimate protocols and public infrastructure for C2 resilience, coupled with financial data interception capabilities, positions it as a significant emerging risk in the cybercrime ecosystem.

IOCs

DomainFirst SeenURL
chubrik\[.\]sbs2026-05-09hxxps://chubrik\[.\]sbs/files/xK7mR9pL2nQw5tY8/ygvfuyze.dll
betalegenda\[.\]cfd2026-05-14hxxps://betalegenda\[.\]cfd/files/xK7mR9pL2nQw5tY8/kmwvogwx.dll
mavpaprokla\[.\]lat2026-05-19hxxps://mavpaprokla\[.\]lat/files/telemetriawork/telepuz.dll
comicstar\[.\]lat2026-05-26hxxps://comicstar\[.\]lat/files/telemetriawork/telepuz.dll
bigblower\[.\]click2026-05-28hxxps://bigblower\[.\]click/files/telemetriawork/telepuz.dll
momasites\[.\]lol2026-06-05hxxps://momasites\[.\]lol/files/telemetriawork/telepuz.dll
momasites\[.\]com2026-06-07hxxps://momasites\[.\]com/files/telemetrywork/telepuz
mamsites\[.\]lol2026-06-07hxxps://mamsites\[.\]lol/files/telemetrywork/telepuz.dll
hardenedom\[.\]shop2026-06-07hxxps://hardenedom\[.\]shop/files/telemetriawork/telepuz.dll
hardendedom\[.\]shop2026-06-07hxxps://hardendedom\[.\]shop/files/lemetriawork/epuz.dll
hardendom\[.\]shop2026-06-08hxxps://hardendom\[.\]shop/files/telemetry/telepuz.dll
hardeneddom\[.\]shop2026-06-10hxxps://hardeneddom\[.\]shop/files/telemetrywork/telepuz
netblokirovka\[.\]asia2026-06-11hxxps://netblokirovka\[.\]asia/files/telemetriawork/telepuz.dll
netblokir\[.\]asia2026-06-12hxxps://netblokir\[.\]asia/files/telemetriawork/telepuz.dll
netlobikrovka\[.\]asia2026-06-14hxxps://netlobikrovka\[.\]asia/files/telemetriawork/telepuz.dll
neblokirovka\[.\]as2026-06-15hxxps://neblokirovka\[.\]as/telemetry/network/telepuz.dll
kidsko\[.\]shop2026-06-17hxxps://kidsko\[.\]shop/files/telemetriawork/telepuz.dll
mazaporka\[.\]shop2026-06-22hxxps://mazaporka\[.\]shop/files/telemetriawork/telepuz.dll
172.67.215[.]2142026-06-24hxxps://172.67.215[.]214/files/telemetriawork/telepuz.dll
hurgadatour\[.\]shop2026-06-25hxxps://hurgadatour\[.\]shop/files/telemetriawork/telepuz.dll
krabsburger\[.\]xyz2026-06-29hxxp://krabsburger\[.\]xyz/files/telemetriawork/telepuz.dll
zewaplus\[.\]club2026-06-30hxxps://zewaplus\[.\]club/files/telemetriawork/telepuz.dll
172.67.165[.]1442026-07-06hxxps://172.67.165[.]144/files/telemetriawork/telepuz.dll

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

𝗔𝗜 𝗦𝗢𝗖 𝘃𝘀 𝗠𝗗𝗥 𝘃𝘀 𝗠𝗦𝗦𝗣 Which is Best in 2026? Compare costs, Automation, and response: Download Free Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News