Skip to content
TELEPUZ Malware Emerges, Spreading via ClickFix Lures to Steal Data

TELEPUZ Malware Emerges, Spreading via ClickFix Lures to Steal Data

First seen 16 Jul 2026, 23:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 17, 2026 at 21:53 UTC
  • TELEPUZ malware spreads via ClickFix lures, targeting unsuspecting users.
  • It employs advanced evasion techniques to disable security measures.
  • The C2 server utilizes multiple encrypted communication methods.

A new modular malware named TELEPUZ has been detected spreading since late April 2026. It uses ClickFix lures to trick users into executing malicious commands. The malware is lightweight and modular, likely developed by a small team and may be offered as malware-as-a-service. TELEPUZ employs obfuscation techniques to evade detection and disables security monitoring features. It performs anti-virtual machine checks and crashes debuggers before connecting to its command-and-control (C2) server. The C2 server can be accessed through various encrypted methods, including Telegram and blockchain smart contracts. Once connected, TELEPUZ can execute commands, log keystrokes, and extract cookies from browsers. Compromised websites in Brazil and India have been identified as hosting the malware.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 55d ago How this analysis works

Timeline

2026-04-30
TELEPUZ malware first detected
Elastic Security Labs reported the emergence of TELEPUZ malware spreading via ClickFix lures.
The Hacker News
2026-07-16
TELEPUZ malware details published
Reports detail the malware's capabilities, including data theft and command execution.
Thehackernews

More articles in this cluster (3)

Following this threat?

Track Telepuz in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed