ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage — Threadlinqs Intelligence
As of 2026-07-20, ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1558 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Elastic Security Labs is tracking TELEPUZ, a modular malware-as-a-service RAT with 36 remote commands spread since late April 2026 via ClickFix clipboard-hijacking lures that pull a Go-based VIDAR
TELEPUZ is a lightweight, modular Windows RAT written in C, distributed under an apparent malware-as-a-service model evidenced by daily VirusTotal build submissions and steady binary-size growth since campaign onset. Victims are lured through fake browser/verification pages using the ClickFix social-engineering technique: a spoofed CAPTCHA or update prompt instructs the user to press Win+R and paste a clipboard-hijacked PowerShell command, which fetches a Go-based VIDAR variant from hurgadatour[.]shop. VIDAR downloads and executes two additional components: a small (~13-15KB) stager, install.exe, and the main 64-bit payload, telepuz.dll, launched via rundll32.exe. telepuz.dll establishes a WebSocket (optionally TLS-wrapped) connection to a primary C2 domain and communicates using a JSON-based protocol with a hashed 36-command set (XOR-based hashing, initial value 0x1505). Before beaconing, the malware performs extensive anti-analysis: hardware/resource checks (rejects <2 CPUs, <2GB RAM, low disk), CIS-country geofencing via LCID, sandbox/researcher username and computer-name blacklists, hypervisor display-device detection, NTDLL unhooking, AMSI/ETW patching, DLL notification-callback removal, and multi-layered debugger detection (including infinite-sleep on detection). Persistence is achieved by registering a Windows service (commonly named CipherAllocator, alternately PilotmasterMast) and dropping the DLL under disguised paths in %AppData% or %ProgramData%. Privilege escalation uses a COM elevation moniker, AppInfo ALPC abuse, and token theft from privileged system processes (spoolsv.exe, msdtc.exe, WmiPrvSE.exe, svchost.exe). Core capabilities include file/process enumeration and manipulation, screenshot capture, keystroke logging, Chromium cookie extraction via a downloaded chromeelevator module, and a Chrome DevTools Protocol/WebDriver BiDi-based web-injection module that swaps form fields (e.g., IBAN substitution) on financial sites without traditional code injection. If primary WebSocket C2 domains are unreachable, TELEPUZ recovers a fallback address by decrypting content pulled from a Telegram channel (t.me/chanadarkpart, XOR key 'Goodman'), a Steam Community profile's name-history field, a DNS TXT-style lookup against codebasecode.com, or a Polygon blockchain smart contract (AES-256-CBC decryption), the last of which doubles as an operator-controlled kill switch. As of the July 2026 Elastic Security Labs disclosure the shellcode-injection command remained an unimplemented TODO, underscoring the malware's active, rapid development by what is assessed to be a small team or solo developer. This is the second ClickFix-delivered threat cluster Elastic has tracked in this timeframe, following SCMBANKER.
Target sectors: financial services, general consumer enterprise broad opportunistic targeting
Target regions: Global (excludes CIS: Ukraine, Belarus, Armenia, Azerbaijan, Tajikistan, Georgia, Kazakhstan, Kyrgyzstan, Turkmenistan, Uzbekistan, Moldova)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1608, T1566, T1204, T1059, T1106, T1129, T1569, T1203, T1543