VMTech
Discuss a project

TELEPUZ via ClickFix: a new modular threat for data theft and remote commands

TELEPUZ via ClickFix: a new modular threat for data theft and remote commands

Colleagues, I’d like to highlight a new cybersecurity threat: TELEPUZ.

The malware spreads via ClickFix, where users are prompted to manually run malicious commands under the guise of a fix or verification.

It then launches PowerShell, downloads a second stage, and uses Vidar Stealer to exfiltrate data.

TELEPUZ can evade analysis by checking virtual environments and geolocation, disabling AMSI/ETW, and escalating privileges.

It then contacts its C2, collects cookies, takes screenshots, executes commands, and can load additional modules.

Why it matters: campaigns like this show how social engineering and modular malware are rapidly complicating defense.

Have you encountered ClickFix in your investigations?

Open analytics
On the site 8 views
min read 1 16.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

TELEPUZ via ClickFix: a new modular threat for data theft and remote commands

Open the post on Instagram ↗