Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Outlook Vulnerability Lets Attackers Hide C2 in Calendar Events
July 21, 2026
Critical Langflow Flaw Lets JADEPUFFER Deploy ENCFORGE AI Ransomware
July 21, 2026
Abbott Investigates ShinyHunters Data Breach Claim Affecting Healthcare Systems
July 21, 2026
Home/CyberSecurity News/ClickFix Campaign Delivers TELEPUZ Malware with 36 Remote Commands
CyberSecurity News

ClickFix Campaign Delivers TELEPUZ Malware with 36 Remote Commands

Key Takeaways A new malware campaign, dubbed “ClickFix,” is actively distributing the modular TELEPUZ malware to Windows users. The attack leverages deceptive “ClickFix” web...

David kimber
David kimber
July 20, 2026 4 Min Read
4 0

Key Takeaways

  • A new malware campaign, dubbed “ClickFix,” is actively distributing the modular TELEPUZ malware to Windows users.
  • The attack leverages deceptive “ClickFix” web pages that trick users into manually executing malicious commands.
  • TELEPUZ is a sophisticated remote access trojan (RAT) with 36 distinct commands, enabling extensive control over infected systems.
  • The malware employs advanced evasion techniques and multiple persistence mechanisms, making detection and removal challenging.
  • Researchers have observed rapid development and increased activity of TELEPUZ since late April 2026, indicating an expanding threat.

A sophisticated new malware campaign, dubbed “ClickFix,” is actively targeting Windows users by employing deceptive web pages to deliver the potent TELEPUZ remote access malware. This operation leverages social engineering to persuade victims into executing malicious commands themselves, initiating a multi-stage infection process.

Table Of Content

  • Key Takeaways
  • Modular Design and Extensive Capabilities
  • Evasion and Defensive Steps
  • What You Should Do

TELEPUZ, a lightweight yet highly capable remote-access malware, grants its operators a broad spectrum of control over compromised systems, with the capacity to execute dozens of remote instructions. The initial vector involves fake verification pages that prompt visitors to copy and paste a command, leading to the download of a secondary payload.

This malicious action subsequently fetches a VIDAR-based second-stage component. This component then retrieves the TELEPUZ loader and its primary payload, following a pattern consistent with recent ClickFix campaigns that exploit user interaction for initial access, according to a comprehensive report by Elastic, shared with Cyber Security News (CSN).

Elastic’s research indicates that TELEPUZ has been operational since late April 2026 and is undergoing rapid development. Analysts have noted a consistent stream of new builds and a significant surge in activity since early June, suggesting a rapid expansion of the campaign.

Modular Design and Extensive Capabilities

TELEPUZ is engineered with a modular architecture, initially maintaining a small footprint. This design allows it to dynamically download additional functionalities as required, avoiding the inclusion of all capabilities in the initial deployment file. This modularity enables operators to selectively deploy features such as information stealing, keystroke logging, browser manipulation, and other malicious functions post-infection.

Communication with its command-and-control (C2) server is conducted via WebSockets, utilizing a JSON-based protocol for data exchange and task reception. Should direct contact with the primary C2 server fail, TELEPUZ is equipped with robust fallback mechanisms, attempting to establish communication through alternative channels including Telegram, a Steam profile, DNS records, or even a Polygon blockchain smart contract.

The malware boasts an impressive array of 36 distinct commands, providing attackers with extensive control over an infected device. These commands facilitate a wide range of malicious activities, including executing arbitrary commands, enumerating files and processes, capturing screenshots, exfiltrating data, creating ZIP archives, deleting files, modifying beacon intervals, updating the malware itself, and terminating processes.

Several of TELEPUZ’s commands are specifically designed for credential theft and subsequent network intrusion. It can deploy a stealer module, initiate a keylogger, extract cookies from Chromium-based browsers, download additional malware modules, and execute files within hollowed processes. This functionality positions TELEPUZ among the advanced threats that specifically target browser credentials and session cookies.

Furthermore, the malware incorporates a sophisticated web-injection module capable of interacting with both Chromium-based browsers and Firefox. This component goes beyond traditional browser code injection, leveraging browser debugging interfaces to intercept web pages, execute JavaScript, manage browser rules, and potentially manipulate financial form fields to steal sensitive information.

Evasion and Defensive Steps

TELEPUZ incorporates advanced evasion techniques to hinder detection and analysis. Before initiating its core operations, the malware performs checks to determine if it is executing within a virtual machine, sandbox, debugger, or an excluded geographic region. It also employs encrypted strings, dynamic API lookups, indirect system calls, and applies patches designed to degrade Windows antimalware scanning and event tracing capabilities.

For persistence, TELEPUZ can copy itself from temporary directories, relaunch via rundll32.exe, bypass User Account Control (UAC), steal elevated access tokens, and register itself as a Windows service. These persistent mechanisms ensure that a simple “ClickFix” error can evolve into a long-term compromise, significantly complicating incident response and forensic investigations.

What You Should Do

  • User Education: Implement rigorous cybersecurity awareness training, emphasizing the dangers of pasting commands from untrusted browser prompts into system tools like Run, Command Prompt, or PowerShell.
  • Monitoring and Blocking: Actively monitor for unusual PowerShell and rundll32.exe activity. Implement DNS and web filtering to block known malicious indicators of compromise (IoCs) and isolate any suspected endpoints immediately.
  • Browser Session Security: In the event of a confirmed infection, prioritize browser session theft mitigation. Reset all exposed passwords, revoke active user sessions, rotate privileged credentials, and thoroughly review browser data for unauthorized access or modifications.
  • Endpoint Detection and Response (EDR): Utilize EDR solutions to detect unusual module downloads and outbound WebSocket traffic, which are key indicators of TELEPUZ activity.
  • Threat Intelligence: Integrate the provided Indicators of Compromise (IoCs) into your security information and event management (SIEM) and threat intelligence platforms (e.g., MISP, VirusTotal). Remember to “re-fang” defanged indicators (e.g., changing [.] to .) only within controlled environments.
Type Indicator Description
URL hxxps://memshowblob[.]forum/api/index.php?a=grab ClickFix-delivered second-stage download URL
SHA-256 580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954 VIDAR Go variant
SHA-256 03fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746 TELEPUZ stager
Domain hurgadatour[.]shop TELEPUZ stager and payload hosting domain
File name install.exe TELEPUZ stager
File name telepuz.dll TELEPUZ main payload
Domain chubrik[.]sbs Staging domain
URL hxxps://chubrik[.]sbs/files/xK7mR9pL2nQw5tY8ygvfuyze.dll Third-stage payload URL
Domain betalegenda[.]cfd Staging domain
URL hxxps://betalegenda[.]cfd/files/xK7mR9pL2nQw5tY8kmwvogwx.dll Third-stage payload URL
Domain mavpaprokla[.]lat Staging domain
URL hxxps://mavpaprokla[.]lat/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain comicstar[.]lat Staging domain
URL hxxps://comicstar[.]lat/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain bigblower[.]click Staging domain
URL hxxps://bigblower[.]click/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain momasites[.]lol Staging domain
URL hxxps://momasites[.]lol/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain momasites[.]com Staging domain
URL hxxps://momasites[.]com/files/telemetrywork/telepuz Third-stage payload URL
Domain mamsites[.]lol Staging domain
URL hxxps://mamsites[.]lol/files/telemetrywork/telepuz.dll Third-stage payload URL
Domain hardenedom[.]shop Staging domain
URL hxxps://hardenedom[.]shop/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain hardendedom[.]shop Staging domain
URL hxxps://hardendedom[.]shop/files/lemetriawork/epuz.dll Third-stage payload URL
Domain hardendom[.]shop Staging domain
URL hxxps://hardendom[.]shop/files/telemetry/telepuz.dll Third-stage payload URL
Domain hardeneddom[.]shop Staging domain
URL hxxps://hardeneddom[.]shop/files/telemetrywork/telepuz Third-stage payload URL
Domain netblokirovka[.]asia Staging domain
URL hxxps://netblokirovka[.]asia/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain netblokir[.]asia Staging domain
URL hxxps://netblokir[.]asia/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain netlobikrovka[.]asia Staging domain
URL hxxps://netlobikrovka[.]asia/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain neblokirovka[.]as Staging domain
URL hxxps://neblokirovka[.]as/telemetrynetwork/telepuz.dll Third-stage payload URL
Domain kidsko[.]shop Staging domain
URL hxxps://kidsko[.]shop/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain mazaporka[.]shop Staging domain
URL hxxps://mazaporka[.]shop/files/telemetriawork/telepuz.dll Third-stage payload URL
IP address 172.67.215.214 Staging infrastructure IP
URL hxxps://172.67.215.214/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain krabsburger[.]xyz Staging domain
URL hxxp://krabsburger[.]xyz/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain zewaplus[.]club Payload hosting domain
URL hxxps://zewaplus[.]club/files/telemetriawork/telepuz.dll Third-stage payload URL
IP address 172.67.165.144 Staging infrastructure IP
URL hxxps://172.67.165.144/files/telemetriawork/telepuz.dll Third-stage payload URL
Domain cal.joycedoula[.]com[.]br Primary TELEPUZ command-and-control domain
Domain cal.snehamumbai[.]org Fallback command-and-control domain
Telegram t[.]me/chanadarkpart Telegram fallback C2 retrieval channel
URL hxxps://steamcommunity[.]com/profiles/76561199705801219 Steam profile used for fallback C2 retrieval
Domain codebasecode[.]com DNS-based fallback C2 lookup domain
Blockchain address 0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753E Polygon smart contract used for fallback C2 retrieval
SHA-256 58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed Reference TELEPUZ main payload
SHA-256 bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343 TELEPUZ main payload
SHA-256 ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e TELEPUZ main payload
SHA-256 a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3 TELEPUZ keylogger module
SHA-256 9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477eb TELEPUZ stealer module
SHA-256 444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1 TELEPUZ web-injector module
Mutex cfgmgrmtx TELEPUZ mutex
Mutex bginfodmtx TELEPUZ mutex
Mutex wfj64mtx TELEPUZ mutex
File name AppData.dll TELEPUZ persistence artifact
File name ProgramData.dll TELEPUZ installation artifact
File name agent.dll TELEPUZ installation artifact

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Microsoft Ends OneDrive Sync App Updates for Windows 10

Next Post

Critical RCE in Wp2shell Could Fetch $500,000 on Exploit Markets

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Linux Kernel Patches Over 400 Vulnerabilities
July 21, 2026
Security Alert Uncovers GenAI Malware Factory with 1,000+ Attack Files
July 21, 2026
Critical Gitea CVE-2024-4696 allows private repo writes, workflow triggers
July 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us