TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain — Threadlinqs Intelligence
As of 2026-07-20, TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 54 indicators of compromise.
Threat ID: TL-2026-1557 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
TELEPUZ is a modular, 64-bit C-language DLL malware operated as a likely Malware-as-a-Service (MaaS) platform. It is distributed via ClickFix social-engineering lures that trigger PowerShell execution
TELEPUZ is a lightweight, modular malware family written in C, first observed spreading in the wild since late April 2026 and submitted to VirusTotal starting May 2, 2026, per Elastic Security Labs research. The infection chain begins with a ClickFix social-engineering lure — deceptive fake CAPTCHA/verification web content that tricks victims into pasting and executing a malicious PowerShell command themselves. That PowerShell command retrieves a Go-language variant of the VIDAR infostealer/downloader from staging infrastructure such as memshowblob[.]forum/api/index.php?a=grab. VIDAR then downloads and executes the TELEPUZ stager (install.exe, ~13-15KB) which in turn fetches and loads the main payload (telepuz.dll) via rundll32.exe, staged from domains such as hurgadatour[.]shop and mavpaprokla[.]lat.
Once resident, TELEPUZ establishes persistence via Windows service creation (registry keys under HKLM\SYSTEM\CurrentControlSet\Services\CipherAllocator and PilotmasterMast) and drops copies into deceptively named AppData/ProgramData paths (e.g., etwhost.dll, systemreset.dll, dsp_agent.dll) to blend with legitimate system components. It escalates privileges through a COM elevation moniker (ShellExecute UAC bypass) and an AppInfo ALPC + DebugObjects technique, then steals access tokens from privileged processes (spoolsv.exe, msdtc.exe, WmiPrvSE.exe, svchost.exe) to operate at SYSTEM.
TELEPUZ implements extensive anti-analysis tradecraft: NTDLL unhooking, AMSI (AmsiScanBuffer) and ETW (EtwEventWrite, NtTraceEvent, NtTraceEventControl) patching, DLL notification-callback removal, hardware/VM fingerprinting (CPU count, RAM, disk size, hypervisor device-name checks), sandbox username/computer-name blocklists, multi-layer debugger detection (NtQueryInformationProcess, hardware breakpoints, ThreadHideFromDebugger, PEB.BeingDebugged, and a deliberate NtClose(0xDEADBEEF) crash-on-debug), and CIS-country geofencing via LCID validation. Obfuscation includes garbage-instruction interleaving, custom rotate/XOR import hashing, per-sample RC4 string encryption, and indirect syscalls executed through trampoline stubs patched into unrelated system DLLs (dfscli.dll, davhlpr.dll, msdtclog.dll, dsrole.dll, secur32.dll).
Command and control runs primarily over a manually implemented WebSocket protocol (optional TLS via SChannel) to a rotating set of C2 domains (cal.joycedoula[.]com[.]br, cal.snehamumbai[.]org — largely compromised legitimate sites in Brazil and India, fronted by Cloudflare). Session identifiers are derived from hardware serial, computer name, and OS install date via FNV1-32 hashing and a custom ROR27 algorithm. If the primary C2 becomes unreachable, TELEPUZ falls back through four redundant resolution channels: a Telegram profile (t.me/chanadarkpart, XOR-keyed with 'Goodman'), a Steam Community profile (76561199705801219), plain DNS queries (codebasecode[.]com), and reads from a Polygon blockchain smart contract (0xf55Bea1FdCf1c3ABb39ab92567C09aC1BFf6753E) decrypted with a hardcoded AES-256-CBC key — giving the operators takedown-resistant, decentralized C2 resolution.
TELEPUZ supports 36+ hashed commands covering file operations, process enumeration/kill, screenshot capture, privilege escalation/token theft, and — critically — on-demand loading of three malicious modules over the same C2 channel: a keylogger, an infostealer (including a dedicated Chrome-cookie extraction routine using a downloaded 'Chrome elevator' helper), and the WebInjector. The WebInjector is a separate PE that communicates with the TELEPUZ core over STDIN/STDOUT/STDERR pipes and receives its JSON configuration over STDIN. Rather than hooking or injecting into the browser process, it drives Chromium browsers remotely via the Chrome DevTools Protocol (attaching to debug ports 9222-9229) and Firefox via the WebDriver BiDi protocol. Its default configuration performs real-time man-in-the-browser banking fraud: URL-matched interception of banking-site network tra
Target sectors: finance, banking, retail-banking-customers
Target regions: brazil, india, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 54 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1059, T1106, T1129, T1569, T1218, T1543, T1112, T1548, T1134, T1134