216.73.216.30

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

· Published 16/07/2026 04:29

Export JSON

Essential information

Published
16/07/2026 04:29
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
clickfix maas telepuz vidar
Related entities
13 indicators, 4 observables, 2 malware

Description

TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through - infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service.

External references