New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

July 16, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: General internet users and corporate workstations
Incident: Deployment of TELEPUZ malware via ClickFix social engineering lures.
Impact: Loss of sensitive browser data and potential for remote command execution.
Attacker: Unidentified threat actor (likely a small MaaS operation)
Analysis: TELEPUZ employs a multi-stage delivery chain starting with clipboard hijacking to trick users into executing malicious PowerShell commands. The malware features advanced evasion capabilities, including anti-VM checks and the disabling of AMSI and ETW. Once active, it leverages the Chrome DevTools Protocol to steal cookies and execute arbitrary JavaScript in the browser.
Recommendations: Train users to never paste commands from websites into PowerShell or command prompts.; Monitor for suspicious rundll32.exe activity and unauthorized PowerShell executions.; Implement network-level blocking for known ClickFix staging domains and C2 infrastructure.
Source: The Hacker News / Elastic Security Labs

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *