Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TELEPUZ Malware Tactics Exploit ClickFix for 36 Commands

TELEPUZ Malware Tactics Exploit ClickFix for 36 Commands

Posted on July 20, 2026 By CWS

A recent cybersecurity threat has emerged, leveraging ClickFix pages to deceive Windows users into executing harmful commands. This operation introduces TELEPUZ, a streamlined but robust malware designed to receive and execute a wide range of instructions from its controllers.

Modus Operandi of TELEPUZ Campaign

The infiltration begins with a counterfeit verification page, prompting users to run a command. This action initiates a VIDAR-based secondary stage, which subsequently downloads the TELEPUZ loader and main payload. This method mirrors previous ClickFix campaigns, transforming user actions into points of entry.

According to a report by Elastic, shared with Cyber Security News (CSN), TELEPUZ has been operational since late April 2026, with significant activity spikes observed by early June. This indicates rapid expansion and evolution of the operation.

Capabilities and Communication

TELEPUZ is designed to remain minimal initially, with the ability to add functions as needed. This modular approach allows operators to incorporate data theft, keystroke logging, and browser manipulation without burdening the initial payload with all features.

Utilizing WebSockets, TELEPUZ communicates with its command-and-control server, employing a JSON-based protocol for data exchange. If the primary server contact fails, it can switch to alternative infrastructures via Telegram, Steam profiles, DNS records, or a Polygon blockchain smart contract.

Defensive Measures and Evasion Techniques

Before executing its main tasks, TELEPUZ verifies its environment, checking for virtual machines, sandboxes, debuggers, or geolocation restrictions. It employs encrypted strings, dynamic API lookups, and indirect system calls to circumvent Windows security measures.

To maintain persistence, TELEPUZ can replicate itself from temporary directories, exploit rundll32.exe, bypass User Account Control, and register as a Windows service. Such tactics ensure the malware’s continued operation and complicate removal efforts.

Recommendations for Organizations

Organizations are advised to train their users against executing commands prompted by browsers and to monitor unusual PowerShell and rundll32.exe activities. Blocking known indicators and employing DNS and web filtering are also recommended to mitigate this threat.

In the event of a confirmed TELEPUZ infection, security teams should prioritize browser-session theft response. This includes resetting exposed passwords, revoking active sessions, and rotating privileged credentials while closely monitoring endpoint activities for suspicious module downloads and outbound WebSocket traffic.

Cyber Security News Tags:browser security, ClickFix, command-and-control, credential theft, cyber attack, Cybersecurity, Elastic report, endpoint security, Malware, remote access, sandbox evasion, TELEPUZ, threat detection, web-injection, Windows

Post navigation

Previous Post: Neo Unveils $100M Investment to Secure AI Software
Next Post: HollowGraph Malware Exploits Microsoft 365 Calendars

Related Posts

Five Hackers Behind Notorious Data Selling Platform BreachForums Arrested Five Hackers Behind Notorious Data Selling Platform BreachForums Arrested Cyber Security News
Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware Cyber Security News
7-Zip Flaw Risks Remote Code Execution for Millions 7-Zip Flaw Risks Remote Code Execution for Millions Cyber Security News
‘The Gentlemen’ Ransomware Group with Dual-Extortion Strategy Encrypts and Exfiltrates Data ‘The Gentlemen’ Ransomware Group with Dual-Extortion Strategy Encrypts and Exfiltrates Data Cyber Security News
Multiple Django Vulnerabilities Enables SQL Injection and Denial-of-Service Attacks Multiple Django Vulnerabilities Enables SQL Injection and Denial-of-Service Attacks Cyber Security News
New Threat: NWHStealer Uses Bun Loader and Encrypted C2 New Threat: NWHStealer Uses Bun Loader and Encrypted C2 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark