TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service.
· unknown severity · unattributed attribution
Evidence and provenance
- Original source
- AlienVault OTX report ↗
- Published
- 2026-07-16T10:18:27.259000Z
- Confidence basis
- No actor match
- Record ID
1a4e28bb25305d563b62
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.