TELEPUZ via ClickFix: a new modular threat for data theft and remote commands

Colleagues, I’d like to highlight a new cybersecurity threat: TELEPUZ.
The malware spreads via ClickFix, where users are prompted to manually run malicious commands under the guise of a fix or verification.
It then launches PowerShell, downloads a second stage, and uses Vidar Stealer to exfiltrate data.
TELEPUZ can evade analysis by checking virtual environments and geolocation, disabling AMSI/ETW, and escalating privileges.
It then contacts its C2, collects cookies, takes screenshots, executes commands, and can load additional modules.
Why it matters: campaigns like this show how social engineering and modular malware are rapidly complicating defense.
Have you encountered ClickFix in your investigations?

