THREAT OPS › Threat News › TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
<p>Elastic Security Labs is tracking an emerging threat named TELEPUZ, which we have discovered spreading widely via a CLICKFIX-VIDAR chain. This malware is in active development and has been operating since late April 2026, according to the infrastructure information we collected. The malware is full-featured, lightweight, and modular. While the number of C2 domains is currently small, the daily
Attributed threat actors
- Earth LuscaG1006
MITRE ATT&CK techniques
- Screen CaptureT1113
- System Owner/User DiscoveryT1033
- Shared ModulesT1129
- Encrypted/Encoded FileT1027.013
- JavaScriptT1059.007
- Create or Modify System ProcessT1543
- Steal Web Session CookieT1539
- Bypass User Account ControlT1548.002
- Windows ServiceT1543.003
- System ChecksT1497.001
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Native APIT1106
- Credentials from Password StoresT1555
- Archive via LibraryT1560.002
- Social EngineeringT1684
- MasqueradingT1036
- Process InjectionT1055
- System Binary Proxy ExecutionT1218
- Reflective Code LoadingT1620
- Security Support ProviderT1547.005
- Archive Collected DataT1560
- Browser Session HijackingT1185
- Modify RegistryT1112
- Abuse Elevation Control MechanismT1548
- Create Process with TokenT1134.002
- Command and Scripting InterpreterT1059
- Indicator RemovalT1070
- File and Directory DiscoveryT1083
- Virtualization/Sandbox EvasionT1497
- Web ServiceT1102
- Process DiscoveryT1057
- Exfiltration Over C2 ChannelT1041
- PowerShellT1059.001
- Process HollowingT1055.012
- Obfuscated Files or InformationT1027
- Encrypted ChannelT1573
- Input CaptureT1056
- CredentialsT1589.001
- Asymmetric CryptographyT1573.002
- System Language DiscoveryT1614.001
- Web Session CookieT1550.004
- System Location DiscoveryT1614
- ImpersonationT1684.001
- System ServicesT1569
- File DeletionT1070.004
- Access Token ManipulationT1134
- Web ProtocolsT1071.001
- Software DiscoveryT1518
- Debugger EvasionT1622
- Ingress Tool TransferT1105
- Dynamic API ResolutionT1027.007
- Service ExecutionT1569.002
- Dead Drop ResolverT1102.001
- Command and Scripting InterpreterAML.T0050
- ImpersonationAML.T0073
- MasqueradingAML.T0074
- Process DiscoveryAML.T0089
- Virtualization/Sandbox EvasionAML.T0097
Indicators of compromise
- 580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954sha256
- 03fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746sha256
- 58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eedsha256
- cee96a38e2dfe31ccf8c3aa7d0d9323e1e3183b2478ba582285822e943d242e9sha256
- d0bba09f1bf9253816511731dd376e1cbbc8437c6225fda8b04c0bf1787236b9sha256
- bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343sha256
- ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3esha256
- a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3sha256
- 9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477ebsha256
- 444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1sha256
- e79481f9c2fcb48fa65aaee451e50c79aae4b372sha1
- 0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753Eeth
- https://memshowblob.forum/api/index.php?a=graburl
- https://www.virustotal.com/gui/file/580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954url
- https://www.virustotal.com/gui/file/03fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746url
- https://www.virustotal.com/gui/file/58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eedurl
- https://steamcommunity.com//profiles/76561199705801219url
- https://www.jsonrpc.org/specificationurl
- https://flask-sock.readthedocs.io/en/latest/index.htmlurl
- https://chromedevtools.github.io/devtools-protocol/url
- https://developer.mozilla.org/en-US/docs/Web/WebDriver/Reference/BiDiurl
- https://www.virustotal.com/gui/file/d0bba09f1bf9253816511731dd376e1cbbc8437c6225fda8b04c0bf1787236b9url
- https://chubrik\url
- https://betalegenda\url
- https://mavpaprokla\url
- https://comicstar\url
- https://bigblower\url
- https://momasites\url
- https://mamsites\url
- https://hardenedom\url
- https://hardendedom\url
- https://hardendom\url
- https://hardeneddom\url
- https://netblokirovka\url
- https://netblokir\url
- https://netlobikrovka\url
- https://neblokirovka\url
- https://kidsko\url
- https://mazaporka\url
- https://172.67.215.214/files/telemetriawork/telepuz.dllurl
Original source: https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix