TELEPUZ Malware Uses ClickFix With Blockchain C2 Fallback

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Elastic Security Labs researcher Cyril François disclosed TELEPUZ, a modular C-based malware spreading via ClickFix-laced websites since late April 2026, noting daily VirusTotal build uploads that signal active development and likely malware-as-a-service distribution.
- TELEPUZ is the second threat cluster after SCMBANKER to use ClickFix clipboard hijacking; the attack chain runs PowerShell to drop a Go-based Vidar Stealer variant, which then launches "telepuz.dll" via rundll32.exe using payloads fetched from hurgadatour[.]shop.
- The malware maintains four fallback C2 recovery paths if primary contact fails: an encrypted URL in a Telegram channel (t[.]me/chanadarkpart, created April 28, 2026), an encrypted URL on a Steam Community profile, a DNS query against codebasecode[.]com, and an encrypted URL embedded in a Polygon blockchain smart contract.
- TELEPUZ geofences by excluding Commonwealth of Independent States countries via locale identifier checks, terminates immediately on sandbox or malware-research usernames, and disables defenses by unhooking NTDLL and turning off AMSI and ETW before opening a WebSocket channel.
- Capabilities include file enumeration, keystroke logging, screenshot capture, command execution, and browser cookie extraction across Chromium-based browsers and Mozilla Firefox via the Chrome DevTools Protocol and WebDriver BiDi protocol.
- The C2 servers have been identified as compromised websites located in Brazil and India, while the staging domains are fronted by Cloudflare to conceal true hosting locations.
Why it matters: TELEPUZ's four-tier fallback C2 — spanning Telegram, Steam, DNS, and a Polygon smart contract — makes takedown substantially harder than ordinary botnets, since defenders cannot easily revoke a blockchain-hosted address. The CIS geofence strongly implies Russian-speaking operators targeting victims outside their region, while the CDP/WebDriver BiDi cookie extraction means a single pasted PowerShell command can hand over authenticated browser sessions.



