As cited
Copy frozen at (site build).
threat intel
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
Elastic Security Labs identified TELEPUZ, a modular malware-as-a-service (MaaS) variant spreading since late April 2026 via CLICKFIX-VIDAR infection chains that begin with social engineering prompts to execute PowerShell commands. The malware is lightweight, written in C, uses WebSockets for communication, and exhibits rapid development with multiple daily builds uploaded to VirusTotal, suggesting active development by a small team or solo developer. TELEPUZ is delivered through a multi-stage infection process starting with VIDAR downloaders that execute stagers and the main DLL payload from command-and-control infrastructure.
Why it matters: Organizations and users targeted by ClickFix campaigns face immediate risk from this emerging, actively developed MaaS malware; defenders should monitor for TELEPUZ and VIDAR payloads, block identified C2 domains, and educate users against copy-paste command execution prompts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
Elastic Security Labs identified TELEPUZ, a modular malware-as-a-service (MaaS) variant spreading since late April 2026 via CLICKFIX-VIDAR infection chains that begin with social engineering prompts to execute PowerShell commands. The malware is lightweight, written in C, uses WebSockets for communication, and exhibits rapid development with multiple daily builds uploaded to VirusTotal, suggesting active development by a small team or solo developer. TELEPUZ is delivered through a multi-stage infection process starting with VIDAR downloaders that execute stagers and the main DLL payload from command-and-control infrastructure.
Why it matters: Organizations and users targeted by ClickFix campaigns face immediate risk from this emerging, actively developed MaaS malware; defenders should monitor for TELEPUZ and VIDAR payloads, block identified C2 domains, and educate users against copy-paste command execution prompts.
- Source published
- First seen by Cybersecurity Tracker