A rapidly evolving malware family dubbed TELEPUZ, a modular and lightweight threat that is gaining traction through a ClickFix–VIDAR infection chain.
Despite a relatively small command-and-control (C2) footprint, the pace of development and distribution suggests an emerging large-scale operation.
The infection begins with ClickFix social engineering, where victims are tricked into executing a malicious PowerShell command under the guise of accessing web content.
This initial stage retrieves a second-stage payload from hxxps://memshowblob[.]forum/api/index.php?a=grab, which deploys a VIDAR variant.
VIDAR then downloads TELEPUZ components, including a stager (install.exe) and the main payload (telepuz.dll), typically hosted on domains such as hurgadatour[.]shop.
The TELEPUZ payload is a 64-bit DLL written in C, designed for stealth, modularity, and efficiency. It employs multiple obfuscation techniques, including garbage instructions, custom RC4-based string encryption, and import hashing.
Additionally, it leverages indirect syscalls by mapping a clean copy of ntdll.dll and constructing syscall trampolines, effectively bypassing API hooks and endpoint detection mechanisms.
Persistence is achieved by installing the malware as a service named “CipherAllocator,” often executed via rundll32.exe within svchost.exe contexts.
TELEPUZ also performs extensive anti-analysis checks, including virtual machine detection, debugger evasion using NtQueryInformationProcess and ThreadHideFromDebugger, and geofencing to avoid execution in CIS countries.
It further disables AMSI and ETW by patching key functions such as AmsiScanBuffer and EtwEventWrite.
Elastic Security Labs Researchers said that, TELEPUZ is already exhibiting characteristics of a potential Malware-as-a-Service (MaaS) offering, with frequent updates and a growing number of samples submitted to VirusTotal.
A notable feature of TELEPUZ is its resilient C2 communication architecture. It uses WebSockets over HTTP or TLS, with endpoints like /cdn/health?sid= for beaconing.

If the primary C2 fails, the malware retrieves fallback infrastructure through unconventional channels, including a Telegram profile (hxxps://t[.]me/chanadarkpart), a Steam profile (https://steamcommunity.com/profiles/76561199705801219).
TELEPUZ Web Injector
DNS queries to codebasecode[.]com, and even the Polygon blockchain via JSON-RPC calls targeting smart contract 0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753E.
These fallback methods use XOR or AES-256-CBC encryption to conceal updated C2 domains such as cal.snehamumbai[.]org.
An alternative UAC bypass using AppInfo ALPC and DebugObjects. The malware first launches a non-elevated winver.exe in debug mode via RAicLaunchAdminProcess to capture its debug object handle.

Functionally, TELEPUZ supports over 30 commands, enabling file operations, process injection, privilege escalation, and module execution. Its modular design allows operators to dynamically load capabilities such as keylogging, credential stealing, and browser data extraction.
One of the most concerning components is its WebInjector module, which targets Chromium-based browsers and Firefox using Chrome DevTools Protocol (https://chromedevtools.github.io/devtools-protocol/) and WebDriver BiDi.
Unlike traditional browser injection, TELEPUZ interacts directly with browser debugging interfaces to intercept traffic and manipulate web sessions.

This enables attackers to steal cookies, execute arbitrary JavaScript, and modify sensitive transaction data in real time.
For example, it can replace IBAN fields during online banking sessions, effectively redirecting funds without user awareness.
The module also supports rule-based actions, including URL matching, field swapping, and response filtering, making it highly adaptable for financial fraud.
Infrastructure analysis reveals limited but strategic C2 usage, primarily through compromised legitimate domains such as cal.joycedoula[.]com[.]br and cal.snehamumbai[.]org.
Meanwhile, staging infrastructure is often protected by Cloudflare, obscuring backend hosting.
VirusTotal telemetry (e.g., https://www.virustotal.com/gui/file/58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed) shows a sharp increase in TELEPUZ sample submissions since early June 2026.
Overall, TELEPUZ represents a sophisticated and flexible threat platform combining modern evasion, modular payload delivery, and advanced browser manipulation.
Its ability to leverage legitimate protocols and public infrastructure for C2 resilience, coupled with financial data interception capabilities, positions it as a significant emerging risk in the cybercrime ecosystem.
IOCs
| Domain | First Seen | URL |
|---|---|---|
chubrik\[.\]sbs | 2026-05-09 | hxxps://chubrik\[.\]sbs/files/xK7mR9pL2nQw5tY8/ygvfuyze.dll |
betalegenda\[.\]cfd | 2026-05-14 | hxxps://betalegenda\[.\]cfd/files/xK7mR9pL2nQw5tY8/kmwvogwx.dll |
mavpaprokla\[.\]lat | 2026-05-19 | hxxps://mavpaprokla\[.\]lat/files/telemetriawork/telepuz.dll |
comicstar\[.\]lat | 2026-05-26 | hxxps://comicstar\[.\]lat/files/telemetriawork/telepuz.dll |
bigblower\[.\]click | 2026-05-28 | hxxps://bigblower\[.\]click/files/telemetriawork/telepuz.dll |
momasites\[.\]lol | 2026-06-05 | hxxps://momasites\[.\]lol/files/telemetriawork/telepuz.dll |
momasites\[.\]com | 2026-06-07 | hxxps://momasites\[.\]com/files/telemetrywork/telepuz |
mamsites\[.\]lol | 2026-06-07 | hxxps://mamsites\[.\]lol/files/telemetrywork/telepuz.dll |
hardenedom\[.\]shop | 2026-06-07 | hxxps://hardenedom\[.\]shop/files/telemetriawork/telepuz.dll |
hardendedom\[.\]shop | 2026-06-07 | hxxps://hardendedom\[.\]shop/files/lemetriawork/epuz.dll |
hardendom\[.\]shop | 2026-06-08 | hxxps://hardendom\[.\]shop/files/telemetry/telepuz.dll |
hardeneddom\[.\]shop | 2026-06-10 | hxxps://hardeneddom\[.\]shop/files/telemetrywork/telepuz |
netblokirovka\[.\]asia | 2026-06-11 | hxxps://netblokirovka\[.\]asia/files/telemetriawork/telepuz.dll |
netblokir\[.\]asia | 2026-06-12 | hxxps://netblokir\[.\]asia/files/telemetriawork/telepuz.dll |
netlobikrovka\[.\]asia | 2026-06-14 | hxxps://netlobikrovka\[.\]asia/files/telemetriawork/telepuz.dll |
neblokirovka\[.\]as | 2026-06-15 | hxxps://neblokirovka\[.\]as/telemetry/network/telepuz.dll |
kidsko\[.\]shop | 2026-06-17 | hxxps://kidsko\[.\]shop/files/telemetriawork/telepuz.dll |
mazaporka\[.\]shop | 2026-06-22 | hxxps://mazaporka\[.\]shop/files/telemetriawork/telepuz.dll |
172.67.215[.]214 | 2026-06-24 | hxxps://172.67.215[.]214/files/telemetriawork/telepuz.dll |
hurgadatour\[.\]shop | 2026-06-25 | hxxps://hurgadatour\[.\]shop/files/telemetriawork/telepuz.dll |
krabsburger\[.\]xyz | 2026-06-29 | hxxp://krabsburger\[.\]xyz/files/telemetriawork/telepuz.dll |
zewaplus\[.\]club | 2026-06-30 | hxxps://zewaplus\[.\]club/files/telemetriawork/telepuz.dll |
172.67.165[.]144 | 2026-07-06 | hxxps://172.67.165[.]144/files/telemetriawork/telepuz.dll |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
𝗔𝗜 𝗦𝗢𝗖 𝘃𝘀 𝗠𝗗𝗥 𝘃𝘀 𝗠𝗦𝗦𝗣 Which is Best in 2026? Compare costs, Automation, and response: Download Free Guide





