Elastic Security Labs has published a deep technical analysis of TELEPUZ, a new modular Malware-as-a-Service (MaaS) active since late April 2026. The malware spreads via a ClickFix social engineering attack that leads to a VIDAR Go infostealer, which then drops the TELEPUZ stager and main payload. TELEPUZ is a lightweight, C-written 64-bit Windows DLL featuring extensive anti-analysis techniques including indirect syscalls, NTDLL unhooking, AMSI/ETW patching, garbage instruction obfuscation, and RC4 string encryption. It communicates with its C2 over WebSockets with TLS, and uses multiple fallback C2 resolution methods including Telegram, Steam profiles, DNS records, and a Polygon blockchain smart contract. The malware supports 36 commands and downloads modular payloads for keylogging, credential stealing, web injection (via Chrome DevTools Protocol), and Chrome cookie extraction. IOCs, hashing algorithms, and MITRE ATT&CK mappings are provided.

18m read timeFrom elastic.co
Post cover image
Table of contents
TELEPUZ infection chain via CLICKFIX-VIDARTELEPUZ technical analysis and internalsTELEPUZ campaign timeline and C2 infrastructureTELEPUZ indicators of compromiseTELEPUZ MITRE ATT&CK tactics and techniquesTELEPUZ YARA detection rule
715 Impressions