Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TELEPUZ Malware Tactics Exploit ClickFix for 36 Commands

TELEPUZ Malware Tactics Exploit ClickFix for 36 Commands

Posted on July 20, 2026 By CWS

A recent cybersecurity threat has emerged, leveraging ClickFix pages to deceive Windows users into executing harmful commands. This operation introduces TELEPUZ, a streamlined but robust malware designed to receive and execute a wide range of instructions from its controllers.

Modus Operandi of TELEPUZ Campaign

The infiltration begins with a counterfeit verification page, prompting users to run a command. This action initiates a VIDAR-based secondary stage, which subsequently downloads the TELEPUZ loader and main payload. This method mirrors previous ClickFix campaigns, transforming user actions into points of entry.

According to a report by Elastic, shared with Cyber Security News (CSN), TELEPUZ has been operational since late April 2026, with significant activity spikes observed by early June. This indicates rapid expansion and evolution of the operation.

Capabilities and Communication

TELEPUZ is designed to remain minimal initially, with the ability to add functions as needed. This modular approach allows operators to incorporate data theft, keystroke logging, and browser manipulation without burdening the initial payload with all features.

Utilizing WebSockets, TELEPUZ communicates with its command-and-control server, employing a JSON-based protocol for data exchange. If the primary server contact fails, it can switch to alternative infrastructures via Telegram, Steam profiles, DNS records, or a Polygon blockchain smart contract.

Defensive Measures and Evasion Techniques

Before executing its main tasks, TELEPUZ verifies its environment, checking for virtual machines, sandboxes, debuggers, or geolocation restrictions. It employs encrypted strings, dynamic API lookups, and indirect system calls to circumvent Windows security measures.

To maintain persistence, TELEPUZ can replicate itself from temporary directories, exploit rundll32.exe, bypass User Account Control, and register as a Windows service. Such tactics ensure the malware’s continued operation and complicate removal efforts.

Recommendations for Organizations

Organizations are advised to train their users against executing commands prompted by browsers and to monitor unusual PowerShell and rundll32.exe activities. Blocking known indicators and employing DNS and web filtering are also recommended to mitigate this threat.

In the event of a confirmed TELEPUZ infection, security teams should prioritize browser-session theft response. This includes resetting exposed passwords, revoking active sessions, and rotating privileged credentials while closely monitoring endpoint activities for suspicious module downloads and outbound WebSocket traffic.

Cyber Security News Tags:browser security, ClickFix, command-and-control, credential theft, cyber attack, Cybersecurity, Elastic report, endpoint security, Malware, remote access, sandbox evasion, TELEPUZ, threat detection, web-injection, Windows

Post navigation

Previous Post: Neo Unveils $100M Investment to Secure AI Software
Next Post: HollowGraph Malware Exploits Microsoft 365 Calendars

Related Posts

macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC Cyber Security News
Google Confirms Potential Compromise of All Salesloft Drift Customer Authentication Tokens Google Confirms Potential Compromise of All Salesloft Drift Customer Authentication Tokens Cyber Security News
Critical XSS Flaws in Foxit PDF Editor Expose Users to Risk Critical XSS Flaws in Foxit PDF Editor Expose Users to Risk Cyber Security News
CISA Warns of Windows SMB Vulnerability Actively Exploited in Attacks CISA Warns of Windows SMB Vulnerability Actively Exploited in Attacks Cyber Security News
Top 5 Best Cybersecurity Companies Leading The Industry Right Now in 2025 Top 5 Best Cybersecurity Companies Leading The Industry Right Now in 2025 Cyber Security News
New TruffleNet BEC Campaign Leverages AWS SES Using Stolen Credentials to Compromise 800+ Hosts New TruffleNet BEC Campaign Leverages AWS SES Using Stolen Credentials to Compromise 800+ Hosts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyberattack Turns Telegram Bots Into Covert Control System
  • Furtex: Advanced Linux Toolkit for Security Experts
  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyberattack Turns Telegram Bots Into Covert Control System
  • Furtex: Advanced Linux Toolkit for Security Experts
  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark