ClickFix Campaign Delivers TELEPUZ Malware with 36 Remote Commands
Key Takeaways A new malware campaign, dubbed “ClickFix,” is actively distributing the modular TELEPUZ malware to Windows users. The attack leverages deceptive “ClickFix” web...
Key Takeaways
- A new malware campaign, dubbed “ClickFix,” is actively distributing the modular TELEPUZ malware to Windows users.
- The attack leverages deceptive “ClickFix” web pages that trick users into manually executing malicious commands.
- TELEPUZ is a sophisticated remote access trojan (RAT) with 36 distinct commands, enabling extensive control over infected systems.
- The malware employs advanced evasion techniques and multiple persistence mechanisms, making detection and removal challenging.
- Researchers have observed rapid development and increased activity of TELEPUZ since late April 2026, indicating an expanding threat.
A sophisticated new malware campaign, dubbed “ClickFix,” is actively targeting Windows users by employing deceptive web pages to deliver the potent TELEPUZ remote access malware. This operation leverages social engineering to persuade victims into executing malicious commands themselves, initiating a multi-stage infection process.
Table Of Content
TELEPUZ, a lightweight yet highly capable remote-access malware, grants its operators a broad spectrum of control over compromised systems, with the capacity to execute dozens of remote instructions. The initial vector involves fake verification pages that prompt visitors to copy and paste a command, leading to the download of a secondary payload.
This malicious action subsequently fetches a VIDAR-based second-stage component. This component then retrieves the TELEPUZ loader and its primary payload, following a pattern consistent with recent ClickFix campaigns that exploit user interaction for initial access, according to a comprehensive report by Elastic, shared with Cyber Security News (CSN).
Elastic’s research indicates that TELEPUZ has been operational since late April 2026 and is undergoing rapid development. Analysts have noted a consistent stream of new builds and a significant surge in activity since early June, suggesting a rapid expansion of the campaign.
Modular Design and Extensive Capabilities
TELEPUZ is engineered with a modular architecture, initially maintaining a small footprint. This design allows it to dynamically download additional functionalities as required, avoiding the inclusion of all capabilities in the initial deployment file. This modularity enables operators to selectively deploy features such as information stealing, keystroke logging, browser manipulation, and other malicious functions post-infection.
Communication with its command-and-control (C2) server is conducted via WebSockets, utilizing a JSON-based protocol for data exchange and task reception. Should direct contact with the primary C2 server fail, TELEPUZ is equipped with robust fallback mechanisms, attempting to establish communication through alternative channels including Telegram, a Steam profile, DNS records, or even a Polygon blockchain smart contract.
The malware boasts an impressive array of 36 distinct commands, providing attackers with extensive control over an infected device. These commands facilitate a wide range of malicious activities, including executing arbitrary commands, enumerating files and processes, capturing screenshots, exfiltrating data, creating ZIP archives, deleting files, modifying beacon intervals, updating the malware itself, and terminating processes.
Several of TELEPUZ’s commands are specifically designed for credential theft and subsequent network intrusion. It can deploy a stealer module, initiate a keylogger, extract cookies from Chromium-based browsers, download additional malware modules, and execute files within hollowed processes. This functionality positions TELEPUZ among the advanced threats that specifically target browser credentials and session cookies.
Furthermore, the malware incorporates a sophisticated web-injection module capable of interacting with both Chromium-based browsers and Firefox. This component goes beyond traditional browser code injection, leveraging browser debugging interfaces to intercept web pages, execute JavaScript, manage browser rules, and potentially manipulate financial form fields to steal sensitive information.
Evasion and Defensive Steps
TELEPUZ incorporates advanced evasion techniques to hinder detection and analysis. Before initiating its core operations, the malware performs checks to determine if it is executing within a virtual machine, sandbox, debugger, or an excluded geographic region. It also employs encrypted strings, dynamic API lookups, indirect system calls, and applies patches designed to degrade Windows antimalware scanning and event tracing capabilities.
For persistence, TELEPUZ can copy itself from temporary directories, relaunch via rundll32.exe, bypass User Account Control (UAC), steal elevated access tokens, and register itself as a Windows service. These persistent mechanisms ensure that a simple “ClickFix” error can evolve into a long-term compromise, significantly complicating incident response and forensic investigations.
What You Should Do
- User Education: Implement rigorous cybersecurity awareness training, emphasizing the dangers of pasting commands from untrusted browser prompts into system tools like Run, Command Prompt, or PowerShell.
- Monitoring and Blocking: Actively monitor for unusual PowerShell and rundll32.exe activity. Implement DNS and web filtering to block known malicious indicators of compromise (IoCs) and isolate any suspected endpoints immediately.
- Browser Session Security: In the event of a confirmed infection, prioritize browser session theft mitigation. Reset all exposed passwords, revoke active user sessions, rotate privileged credentials, and thoroughly review browser data for unauthorized access or modifications.
- Endpoint Detection and Response (EDR): Utilize EDR solutions to detect unusual module downloads and outbound WebSocket traffic, which are key indicators of TELEPUZ activity.
- Threat Intelligence: Integrate the provided Indicators of Compromise (IoCs) into your security information and event management (SIEM) and threat intelligence platforms (e.g., MISP, VirusTotal). Remember to “re-fang” defanged indicators (e.g., changing
[.]to.) only within controlled environments.
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps://memshowblob[.]forum/api/index.php?a=grab |
ClickFix-delivered second-stage download URL |
| SHA-256 | 580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954 |
VIDAR Go variant |
| SHA-256 | 03fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746 |
TELEPUZ stager |
| Domain | hurgadatour[.]shop |
TELEPUZ stager and payload hosting domain |
| File name | install.exe |
TELEPUZ stager |
| File name | telepuz.dll |
TELEPUZ main payload |
| Domain | chubrik[.]sbs |
Staging domain |
| URL | hxxps://chubrik[.]sbs/files/xK7mR9pL2nQw5tY8ygvfuyze.dll |
Third-stage payload URL |
| Domain | betalegenda[.]cfd |
Staging domain |
| URL | hxxps://betalegenda[.]cfd/files/xK7mR9pL2nQw5tY8kmwvogwx.dll |
Third-stage payload URL |
| Domain | mavpaprokla[.]lat |
Staging domain |
| URL | hxxps://mavpaprokla[.]lat/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | comicstar[.]lat |
Staging domain |
| URL | hxxps://comicstar[.]lat/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | bigblower[.]click |
Staging domain |
| URL | hxxps://bigblower[.]click/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | momasites[.]lol |
Staging domain |
| URL | hxxps://momasites[.]lol/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | momasites[.]com |
Staging domain |
| URL | hxxps://momasites[.]com/files/telemetrywork/telepuz |
Third-stage payload URL |
| Domain | mamsites[.]lol |
Staging domain |
| URL | hxxps://mamsites[.]lol/files/telemetrywork/telepuz.dll |
Third-stage payload URL |
| Domain | hardenedom[.]shop |
Staging domain |
| URL | hxxps://hardenedom[.]shop/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | hardendedom[.]shop |
Staging domain |
| URL | hxxps://hardendedom[.]shop/files/lemetriawork/epuz.dll |
Third-stage payload URL |
| Domain | hardendom[.]shop |
Staging domain |
| URL | hxxps://hardendom[.]shop/files/telemetry/telepuz.dll |
Third-stage payload URL |
| Domain | hardeneddom[.]shop |
Staging domain |
| URL | hxxps://hardeneddom[.]shop/files/telemetrywork/telepuz |
Third-stage payload URL |
| Domain | netblokirovka[.]asia |
Staging domain |
| URL | hxxps://netblokirovka[.]asia/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | netblokir[.]asia |
Staging domain |
| URL | hxxps://netblokir[.]asia/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | netlobikrovka[.]asia |
Staging domain |
| URL | hxxps://netlobikrovka[.]asia/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | neblokirovka[.]as |
Staging domain |
| URL | hxxps://neblokirovka[.]as/telemetrynetwork/telepuz.dll |
Third-stage payload URL |
| Domain | kidsko[.]shop |
Staging domain |
| URL | hxxps://kidsko[.]shop/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | mazaporka[.]shop |
Staging domain |
| URL | hxxps://mazaporka[.]shop/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| IP address | 172.67.215.214 |
Staging infrastructure IP |
| URL | hxxps://172.67.215.214/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | krabsburger[.]xyz |
Staging domain |
| URL | hxxp://krabsburger[.]xyz/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | zewaplus[.]club |
Payload hosting domain |
| URL | hxxps://zewaplus[.]club/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| IP address | 172.67.165.144 |
Staging infrastructure IP |
| URL | hxxps://172.67.165.144/files/telemetriawork/telepuz.dll |
Third-stage payload URL |
| Domain | cal.joycedoula[.]com[.]br |
Primary TELEPUZ command-and-control domain |
| Domain | cal.snehamumbai[.]org |
Fallback command-and-control domain |
| Telegram | t[.]me/chanadarkpart |
Telegram fallback C2 retrieval channel |
| URL | hxxps://steamcommunity[.]com/profiles/76561199705801219 |
Steam profile used for fallback C2 retrieval |
| Domain | codebasecode[.]com |
DNS-based fallback C2 lookup domain |
| Blockchain address | 0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753E |
Polygon smart contract used for fallback C2 retrieval |
| SHA-256 | 58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed |
Reference TELEPUZ main payload |
| SHA-256 | bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343 |
TELEPUZ main payload |
| SHA-256 | ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e |
TELEPUZ main payload |
| SHA-256 | a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3 |
TELEPUZ keylogger module |
| SHA-256 | 9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477eb |
TELEPUZ stealer module |
| SHA-256 | 444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1 |
TELEPUZ web-injector module |
| Mutex | cfgmgrmtx |
TELEPUZ mutex |
| Mutex | bginfodmtx |
TELEPUZ mutex |
| Mutex | wfj64mtx |
TELEPUZ mutex |
| File name | AppData.dll |
TELEPUZ persistence artifact |
| File name | ProgramData.dll |
TELEPUZ installation artifact |
| File name | agent.dll |
TELEPUZ installation artifact |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.