THE TELEPUZ malware, tracked by Elastic Security Labs, employs a ClickFix social engineering attack to infect Windows users. Initially, victims are lured to a compromised webpage which prompts them to execute a shell command that retrieves the VIDAR loader, which delivers the TELEPUZ payload. The malware features 36 commands, employs a WebSocket C2 infrastructure, and includes capabilities for keylogging and data theft via browser injection.
Notably, it uses a unique command and control (C2) strategy utilizing various fallback methods including Telegram profiles and blockchain contracts. The malware is still under development, evidenced by incomplete functionalities, and its lightweight, modular design suggests it may be operated by a solo developer or a small team. Recommendations for defense include educating users about command execution and monitoring unusual outbound network traffic.