Executive Summary
In late April 2026, a new modular malware named TELEPUZ began spreading through websites compromised with ClickFix lures. This malware, written in C, is lightweight and modular, indicating active development by a small team or solo developer. The infection chain starts with a ClickFix social engineering lure that downloads and executes a second-stage VIDAR Go variant, leading to the deployment of TELEPUZ. The malware employs various obfuscation techniques, including garbage instructions, import name hashing, string encryption, and indirect system calls, to evade detection. It also performs anti-VM and geolocation checks to avoid execution in sandboxed environments or unauthorized geographic locations. Once active, TELEPUZ disables security monitoring by unhooking NTDLL, turning off Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW), and removing third-party DllNotification callbacks. The malware's modular design allows it to download additional components, such as keyloggers, stealers, and web injectors, enhancing its capabilities to steal sensitive data and execute arbitrary commands on infected systems. The rapid pace of updates and the steady volume of daily builds uploaded to VirusTotal suggest that TELEPUZ is likely offered under a malware-as-a-service (MaaS) model, posing a significant threat to organizations and individuals alike.
The emergence of TELEPUZ highlights the evolving sophistication of malware campaigns leveraging social engineering techniques like ClickFix. The use of modular malware-as-a-service models enables rapid development and deployment of new threats, making it imperative for organizations to stay vigilant and implement robust security measures to detect and prevent such infections.
Why This Matters Now
The emergence of TELEPUZ highlights the evolving sophistication of malware campaigns leveraging social engineering techniques like ClickFix. The use of modular malware-as-a-service models enables rapid development and deployment of new threats, making it imperative for organizations to stay vigilant and implement robust security measures to detect and prevent such infections.
Attack Path Analysis
The TELEPUZ malware campaign begins with users being tricked into executing malicious PowerShell commands via ClickFix lures, leading to the download and execution of a Vidar Stealer variant. This variant facilitates the retrieval and execution of the TELEPUZ payload, which employs various techniques to evade detection and establish persistence. Once active, TELEPUZ communicates with command-and-control servers to receive further instructions and exfiltrate sensitive data from the compromised system.
Kill Chain Progression
Initial Compromise
Description
Users are deceived into executing malicious PowerShell commands through ClickFix lures, initiating the download and execution of a Vidar Stealer variant.
MITRE ATT&CK® Techniques
User Execution: Malicious Copy and Paste
Multi-Stage Channels
Command and Scripting Interpreter: Windows Command Shell
Hijack Execution Flow: DLL Search Order Hijacking
Obfuscated Files or Information: Dynamic API Resolution
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Training and Awareness
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
TELEPUZ infostealer targeting encrypted traffic and egress controls poses critical risk to financial data exfiltration and regulatory compliance violations.
Health Care / Life Sciences
Modular malware threatens HIPAA compliance through data exfiltration capabilities, requiring enhanced zero trust segmentation and encrypted traffic monitoring.
Information Technology/IT
ClickFix distribution method exploits IT infrastructure vulnerabilities, demanding strengthened threat detection and multicloud visibility controls for client protection.
Government Administration
Command-and-control capabilities enable lateral movement through government networks, necessitating immediate east-west traffic security and anomaly response deployment.
Sources
- New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commandshttps://thehackernews.com/2026/07/new-telepuz-malware-spreads-via.htmlVerified
- TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chainshttps://www.hendryadrian.com/telepuz-a-modular-maas-malware-spreading-via-clickfix-vidar-chains/Verified
- ClickFix and removable media lead malware delivery methodshttps://www.techtarget.com/searchsecurity/news/366645832/ClickFix-and-removable-media-lead-malware-delivery-methodsVerified
- Think before you Click(Fix): Analyzing the ClickFix social engineering techniquehttps://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the TELEPUZ malware incident as it would likely limit the malware's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial execution of malicious commands, it would likely limit the malware's ability to communicate with external command-and-control servers, reducing the scope of the compromise.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the malware's ability to exploit elevated privileges by restricting access to sensitive resources, thereby reducing the potential impact of privilege escalation.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the malware's ability to move laterally by enforcing strict segmentation policies, thereby reducing the blast radius of the attack.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the malware's ability to establish command-and-control channels by monitoring and controlling outbound communications, thereby reducing the attacker's control over the compromised system.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the malware's ability to exfiltrate data by enforcing strict egress policies, thereby reducing the risk of data loss.
Aviatrix Zero Trust CNSF would likely reduce the overall impact of the malware by limiting its ability to access critical systems and data, thereby constraining the attacker's objectives.
Impact at a Glance
Affected Business Functions
- Data Security
- System Integrity
- User Credential Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive user credentials and personal information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Educate users on recognizing and avoiding social engineering attacks like ClickFix to prevent initial compromise.



