CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2630

As cited

Copy frozen at (site build).

threat intel

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

Elastic Security Labs identified TELEPUZ, a modular malware-as-a-service (MaaS) variant spreading since late April 2026 via CLICKFIX-VIDAR infection chains that begin with social engineering prompts to execute PowerShell commands. The malware is lightweight, written in C, uses WebSockets for communication, and exhibits rapid development with multiple daily builds uploaded to VirusTotal, suggesting active development by a small team or solo developer. TELEPUZ is delivered through a multi-stage infection process starting with VIDAR downloaders that execute stagers and the main DLL payload from command-and-control infrastructure.

Why it matters: Organizations and users targeted by ClickFix campaigns face immediate risk from this emerging, actively developed MaaS malware; defenders should monitor for TELEPUZ and VIDAR payloads, block identified C2 domains, and educate users against copy-paste command execution prompts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

Elastic Security Labs identified TELEPUZ, a modular malware-as-a-service (MaaS) variant spreading since late April 2026 via CLICKFIX-VIDAR infection chains that begin with social engineering prompts to execute PowerShell commands. The malware is lightweight, written in C, uses WebSockets for communication, and exhibits rapid development with multiple daily builds uploaded to VirusTotal, suggesting active development by a small team or solo developer. TELEPUZ is delivered through a multi-stage infection process starting with VIDAR downloaders that execute stagers and the main DLL payload from command-and-control infrastructure.

Why it matters: Organizations and users targeted by ClickFix campaigns face immediate risk from this emerging, actively developed MaaS malware; defenders should monitor for TELEPUZ and VIDAR payloads, block identified C2 domains, and educate users against copy-paste command execution prompts.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary