TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
TELEPUZ is a rapidly evolving modular MaaS malware delivered via ClickFix social engineering and VIDAR second-stage downloader chains. The 64-bit Windows DLL payload uses indirect syscalls, NTDLL unhooking, AMSI/ETW patching, and custom RC4 encryption for defense evasion, while establishing persistence as a Windows service and communicating over WebSockets with fallback C2 resolution via Telegram, Steam, DNS records, and Polygon blockchain smart contracts. The malware supports 36 commands including process hollowing, keylogging, credential theft, browser cookie extraction, and a WebInjector module that abuses Chrome DevTools Protocol to manipulate financial web forms in real-time.
- domainbetalegenda[.]cfdStaging domain (2026-05-14) hosting TELEPUZ payload at /files/xK7mR9pL2nQw5tY8/kmwvogwx.dll
- domainbigblower[.]clickStaging domain (2026-05-28) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domaincal[.]joycedoula[.]com[.]brPrimary C2 server present in earliest malware configurations; compromised legitimate website hosted in Brazil
- domaincal[.]snehamumbai[.]orgLatest C2 server discovered through Telegram and Polygon blockchain fallback methods; compromised legitimate website hosted in India
- domainchubrik[.]sbsEarly staging domain (2026-05-09) hosting TELEPUZ payload at randomized path /files/xK7mR9pL2nQw5tY8/ygvfuyze.dll
- domaincodebasecode[.]comDNS-based fallback C2 resolver domain queried by malware; no DNS records found yet but malware is designed to extract and decrypt C2 from DNS responses
- domaincomicstar[.]latStaging domain (2026-05-26) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainhardendedom[.]shopStaging domain (2026-06-07) hosting TELEPUZ payload at /files/lemetriawork/epuz.dll
- domainhardendom[.]shopStaging domain (2026-06-08) hosting TELEPUZ payload at /files/telemetry/telepuz.dll
- domainhardeneddom[.]shopStaging domain (2026-06-10) hosting TELEPUZ payload at /files/telemetrywork/telepuz
- domainhardenedom[.]shopStaging domain (2026-06-07) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainhurgadatour[.]shopMost recent staging domain hosting TELEPUZ stager (install.exe) and main binary (telepuz.dll); protected by Cloudflare
- domainkidsko[.]shopStaging domain (2026-06-17) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainkrabsburger[.]xyzStaging domain (2026-06-29) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll via HTTP
- domainmamsites[.]lolStaging domain (2026-06-07) hosting TELEPUZ payload at /files/telemetrywork/telepuz.dll
- domainmavpaprokla[.]latStaging domain (2026-05-19) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainmazaporka[.]shopStaging domain (2026-06-22) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainmemshowblob[.]forumFirst-stage download domain used in ClickFix PowerShell command to deliver VIDAR second-stage payload
- domainmomasites[.]comStaging domain (2026-06-07) hosting TELEPUZ payload at /files/telemetrywork/telepuz
- domainmomasites[.]lolStaging domain (2026-06-05) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainneblokirovka[.]asStaging domain (2026-06-15) hosting TELEPUZ payload at /telemetry/network/telepuz.dll
- domainnetblokir[.]asiaStaging domain (2026-06-12) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainnetblokirovka[.]asiaStaging domain (2026-06-11) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainnetlobikrovka[.]asiaStaging domain (2026-06-14) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- domainzewaplus[.]clubStaging domain (2026-06-30) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll
- ip172[.]67[.]165[.]144Cloudflare proxy IP observed hosting TELEPUZ staging URL (2026-07-06); limited actionability as shared CDN infrastructure
- ip172[.]67[.]215[.]214Cloudflare proxy IP observed hosting TELEPUZ staging URL (2026-06-24); limited actionability as shared CDN infrastructure
- mutexcfgmgr_mtxMutex created by TELEPUZ during execution to prevent multiple instances; created before anti-VM and geolocation checks
- registry_keyHKLM\SYSTEM\CurrentControlSet\Services\CipherAllocatorPersistence mechanism — Windows service registration causing malware DLL to load within new svchost.exe instance; service masquerades as legitimate software
- sha25603fa348b70819296c958c842e7646b3b7efe5fa217ed5098143003c47995a746TELEPUZ stager (13-15 KB PE) that downloads main payload DLL and executes it via rundll32 with specified export name
- sha256444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1TELEPUZ webinjector module downloaded from C2 at /static/modules/yaVaoS3Bw.bin
- sha256580b441e2961739fd26e54e0a0ea08351cb10a51839519fc722cfa39ecd0c954VIDAR Go variant second-stage payload downloaded via ClickFix PowerShell command; responsible for downloading TELEPUZ stager and main binary
- sha25658aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eedReference TELEPUZ main payload — 64-bit Windows shared library with ServiceRoutine export, written in C with modular architecture
- sha2569733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477ebTELEPUZ stealer module downloaded from C2 at /static/modules/W2UMxylgG_.bin
- sha256a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3TELEPUZ keylogger module downloaded from C2 at /static/modules/kMP6HBGEA8.bin
- sha256bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343TELEPUZ main payload sample
- sha256d0bba09f1bf9253816511731dd376e1cbbc8437c6225fda8b04c0bf1787236b9First known TELEPUZ sample submitted to VirusTotal on May 2, 2026
- sha256ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3eTELEPUZ main payload sample
- urlhxxps://memshowblob[.]forum/api/index[.]php?a=grabFirst-stage URL downloaded by ClickFix PowerShell command to retrieve VIDAR second-stage payload
- urlhxxps://steamcommunity[.]com/profiles/76561199705801219Steam profile used as dead drop resolver; profile name contains encrypted C2 address; name history reveals prior C2 domains
- urlhxxps://t[.]me/chanadarkpartTelegram profile used as dead drop resolver; contains XOR-encrypted fallback C2 URL (key: Goodman); channel created late April 2026
Detection / Hunteropenrouter
What Happened
Security researchers have discovered a new type of malicious software called TELEPUZ that is being sold as a service to cybercriminals. It tricks people into running harmful code by showing fake instructions on compromised websites (a technique called ClickFix). Once installed, it can steal passwords, record keystrokes, take screenshots, and even manipulate banking websites in real-time to redirect payments. What makes TELEPUZ particularly hard to block is that it uses multiple backup methods to find its control servers, including hidden messages in Telegram channels, Steam gaming profiles, and blockchain records. Organizations with Windows computers should ensure their security tools are updated, block the known malicious domains listed in this report, and train employees never to copy and paste commands from unfamiliar websites. The malware is still under active development, meaning new versions appear daily and capabilities are expanding.
Key Takeaways
- TELEPUZ is a modular MaaS malware in active development since late April 2026, spreading via CLICKFIX-VIDAR infection chains with 36 commands including keylogging, credential theft, and web injection
- Uses multiple evasion techniques: indirect syscalls via patched legitimate DLLs, NTDLL unhooking, AMSI/ETW patching, garbage instruction obfuscation, and custom RC4 string encryption
- Employs four fallback C2 resolution methods: Telegram profile, Steam profile username, DNS TXT records, and Polygon blockchain smart contract queries — making infrastructure takedown difficult
- WebInjector module abuses Chrome DevTools Protocol (CDP) and WebDriver BiDi to manipulate banking web pages in real-time, specifically targeting IBAN form fields without traditional browser hooking
- Persistence achieved via Windows service creation (CipherAllocator) with UAC bypass through COM elevation moniker and AppInfo ALPC/DebugObjects techniques
Affected Systems
- Windows 64-bit systems
- Chromium-based browsers (Chrome, Edge, etc.)
- Firefox browsers (for web injection module)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: ClickFix social engineering on malicious web page tricks user into copying and executing PowerShell command
- Execution: PowerShell downloads VIDAR Go variant (f322a5fa.exe) from memshowblob.forum to %TEMP% and executes it
- Second Stage: VIDAR downloads TELEPUZ stager (install.exe) and main payload (telepuz.dll) from staging domain (e.g., hurgadatour.shop)
- Persistence: TELEPUZ installs as Windows service 'CipherAllocator' via registry keys, copies DLL to %AppData% or %ProgramData% with legitimate-sounding names
- Privilege Escalation: UAC bypass via COM elevation moniker or AppInfo ALPC/DebugObjects; token theft from SYSTEM processes (spoolsv.exe, msdtc.exe, WmiPrvSE.exe)
- C2: WebSocket communication over TLS with fallback resolution via Telegram, Steam profile, DNS records, and Polygon blockchain smart contract
Detection Availability
- YARA Rules: Yes
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Elastic Security Labs GitHub — YARA rules repository, Elastic Security Labs GitHub — IDA Pro string decryption script
A YARA rule (Windows_Trojan_Telepuz.yar) is available in the Elastic Security Labs protections-artifacts GitHub repository for detecting TELEPUZ payloads. An IDA Pro script (decrypt_stringv2.py) for decrypting TELEPUZ RC4-encrypted strings using the debugger's Appcall feature is also provided in the labs-releases repository.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | TELEPUZ employs multiple defense evasion techniques that may reduce EDR telemetry including indirect syscalls executed from patched legitimate DLLs, NTDLL unhooking via fresh copy mapping, AMSI patching (AmsiScanBuffer returns E_INVALIDARG), and ETW patching (EtwEventWrite, NtTraceEvent, NtTraceEventControl forced to return zero). However, process creation, service creation, file system writes, and registry modifications remain visible through standard EDR sensors. |
| Network Visibility | High | C2 communication uses WebSockets with optional TLS via SChannel, with distinctive URI pattern /cdn/health?sid=. Fallback C2 resolution generates observable network activity: DNS queries to codebasecode.com, HTTP requests to Telegram (t.me/chanadarkpart) and Steam (steamcommunity.com), and JsonRPC POST requests to Polygon blockchain endpoints. Staging domain downloads follow predictable URL patterns containing 'telemetriawork' path component. |
| Detection Difficulty | Hard | TELEPUZ combines indirect syscalls with AMSI/ETW patching and NTDLL unhooking to evade user-mode monitoring. String encryption and dynamic API resolution via hashing prevent static analysis. Use of legitimate platforms (Telegram, Steam, Polygon blockchain) for C2 fallback blends with normal user traffic. WebSockets over TLS may not be inspected by standard proxy infrastructure. However, behavioral indicators like service creation, specific mutex names, and URL path patterns ('telemetriawork') provide viable detection opportunities. |
Required Log Sources
- Sysmon Event ID 1 (Process Creation) — for rundll32.exe execution from unusual paths
- Sysmon Event ID 7 (Image Loaded) — for DLL loading from %AppData% or %ProgramData% and patched legitimate DLLs
- Sysmon Event ID 11 (File Creation) — for payload drops to %TEMP% and persistence directories
- Sysmon Event ID 13 (Registry Value Set) — for service creation under HKLM\SYSTEM\CurrentControlSet\Services
- Windows Security Event ID 4688 (Process Creation)
- Windows System Event Log (Service Control Manager — Event ID 7045 for new service creation)
- DNS query logs — for codebasecode.com queries and staging domain resolution
- Proxy / web gateway logs — for WebSocket connections, Telegram/Steam access, Polygon RPC calls
- EDR memory scanning — for process hollowing detection in dllhost.exe
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for rundll32.exe loading DLLs from %AppData% or %ProgramData% directories with legitimate-sounding names (e.g., etwhost.dll, grpeng.dll, dsp_agent.dll), particularly when the parent process is svchost.exe or another rundll32.exe instance | EDR process telemetry, Sysmon Event ID 1 (Process Creation) and Event ID 7 (Image Loaded) | Execution / Persistence | Medium — legitimate software may use rundll32 from AppData, but the specific directory names (DCFG\Runtime\Themes\Processor, XeroxPrint\Temp\Worker, Jundrax\Tracker) are highly suspicious |
| Consider hunting for processes making WebSocket connections to URIs matching the pattern /cdn/health?sid= followed by a hex string session identifier, as this is the TELEPUZ C2 beacon pattern | Network proxy logs with TLS inspection, EDR network telemetry, Zeek/Suricata network flow data | Command and Control | Low — the specific URI path and parameter combination is distinctive and unlikely to appear in legitimate traffic |
| Consider hunting for service creation with names like 'CipherAllocator' or 'PilotmasterMast' that do not correspond to known legitimate software, particularly when the service binary path points to a DLL loaded via rundll32.exe in a svchost group | Windows System Event Log (Service Control Manager Event ID 7045), Sysmon Event ID 13 (Registry Value Set), EDR service creation events | Persistence | Low — the service names are specific and not associated with legitimate Windows or common enterprise software |
| Consider hunting for processes making HTTP requests to Telegram (t.me/chanadarkpart) or Steam community profiles, or DNS queries for codebasecode.com, particularly from non-browser processes or in environments where these platforms are not business-relevant — these are TELEPUZ C2 fallback resolution methods (T1102.001) | DNS logs, proxy logs, EDR network telemetry | Command and Control | Medium — legitimate access to Telegram and Steam is common on user workstations; focus on non-browser process ancestry and the specific profile/URL |
| Consider hunting for dllhost.exe process creation followed by indicators of process hollowing, as TELEPUZ's DownloadRunPE command creates a dllhost.exe process and performs process hollowing with downloaded PE files | EDR process telemetry with memory scanning capability, Sysmon Event ID 1 and Event ID 8 (CreateRemoteThread) | Execution | Medium — dllhost.exe is a legitimate COM Surrogate process; focus on hollowing indicators and unusual parent-child relationships |
Control Gaps
- AMSI patching may bypass content scanning of scripts and in-memory payloads on affected processes
- ETW patching (EtwEventWrite, NtTraceEvent, NtTraceEventControl) may disable telemetry from affected processes for the duration of infection
- NTDLL unhooking via fresh copy mapping may bypass user-mode API hooks used by EDR products
- Indirect syscalls executed from patched legitimate DLLs (dfscli.dll, davhlpr.dll, msdtclog.dll, dsrole.dll, secur32.dll) may bypass EDR syscall monitoring and API call tracing
- Use of legitimate platforms (Telegram, Steam, Polygon blockchain) for C2 resolution may evade domain blocklists and URL filtering policies
- WebSocket C2 over TLS may not be inspected by standard forward proxy infrastructure that only handles HTTP/HTTPS
- WebInjector module uses Chrome DevTools Protocol (CDP) on ports 9222-9329 and WebDriver BiDi for Firefox, which may not be monitored by endpoint security tools
Key Behavioral Indicators
- rundll32.exe executing DLLs from paths containing DCFG\Runtime\Themes\Processor, XeroxPrint\Temp\Worker, Jundrax\Tracker, QualcommRF, D3DSCache\amd64, StateRepository\Host\Recovery, or MiravaDevices
- Windows service creation with name 'CipherAllocator' or 'PilotmasterMast'
- Mutex creation: cfgmgr_mtx, bginfod_mtx, wfj64_mtx
- Legitimate Windows DLLs (dfscli.dll, davhlpr.dll, msdtclog.dll, dsrole.dll, secur32.dll) loaded and then having their .text section patched — indicates indirect syscall trampoline installation
- dllhost.exe spawned with elevated privileges followed by process hollowing indicators
- WebSocket connections to URI path /cdn/health?sid= with hex session identifier parameter
- WebSocket connections to URI path /ws/inject?cid= indicating WebInjector module direct C2
- DNS queries for codebasecode.com from non-DNS-service processes
- HTTP requests to t.me/chanadarkpart from non-browser processes
- JsonRPC POST requests to Polygon blockchain endpoints with method eth_call targeting contract 0xf55Bea1FdCf1cABb39ab92567C09aC1BFf6753E
- URL paths containing 'telemetriawork' or 'telemetrywork' in HTTP downloads of DLL files
- Registry modifications under HKLM\SYSTEM\CurrentControlSet\Services\CipherAllocator or HKLM\SYSTEM\CurrentControlSet\Services\PilotmasterMast
- Processes spawning winver.exe and computerdefaults.exe in debug mode (AppInfo ALPC UAC bypass technique)
- Chrome DevTools Protocol connections on ports 9222-9329 from non-development processes
False Positive Assessment
Low — The specific indicators such as service names (CipherAllocator, PilotmasterMast), mutex names (cfgmgr_mtx, bginfod_mtx, wfj64_mtx), persistence paths (DCFG\Runtime\Themes\Processor, XeroxPrint\Temp\Worker), and C2 URI patterns (/cdn/health?sid=) are distinctive and unlikely to appear in legitimate software. However, some behavioral indicators like rundll32.exe execution from AppData or DNS queries to Telegram/Steam may generate noise in environments where these platforms are legitimately used.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified C2 domains (cal.joycedoula.com.br, cal.snehamumbai.org) and as many staging domains as feasible at your network perimeter and DNS resolver level.
- Consider searching endpoint telemetry for the identified file hashes, mutex names (cfgmgr_mtx, bginfod_mtx, wfj64_mtx), and registry keys to identify potential existing compromises across your environment.
- If your EDR supports custom detection rules, consider creating behavioral detections for rundll32.exe loading DLLs from the identified persistence paths (DCFG\Runtime\Themes\Processor, XeroxPrint\Temp\Worker, etc.).
- Evaluate whether your DNS logging and proxy infrastructure can detect queries to codebasecode.com and access to the specific Telegram profile (t.me/chanadarkpart) and Steam community URL used as C2 fallback resolvers.
Infrastructure Hardening
- Consider implementing TLS inspection for WebSocket traffic where supported by your proxy infrastructure, as TELEPUZ uses WebSocket over TLS for C2 communication.
- Evaluate whether your network security monitoring can detect and alert on JsonRPC calls to Polygon blockchain endpoints from workstation IP ranges, as this is an unusual C2 fallback method.
- If applicable to your environment, consider restricting access to blockchain RPC endpoints and cryptocurrency-related infrastructure from non-developer workstations.
- Consider implementing DNS response policy zones or similar mechanisms to block the identified staging domains, which follow predictable naming patterns (e.g., *.shop, *.lat, *.asia, *.click, *.lol).
- Evaluate whether your service monitoring can alert on new service creation with unusual names or service binaries pointing to DLLs in non-standard directories.
User Protection
- If your EDR supports behavioral detection of process hollowing, consider enabling or tuning it specifically for dllhost.exe, as TELEPUZ uses this process for executing downloaded PE files.
- Consider deploying or tuning detections for AMSI and ETW patching attempts (AmsiScanBuffer returning E_INVALIDARG, EtwEventWrite returning zero), as these are early indicators of defense evasion.
- Evaluate whether your endpoint protection can detect NTDLL unhooking via fresh copy mapping and indirect syscall execution from patched legitimate DLLs.
- Consider monitoring for Chrome DevTools Protocol connections on ports 9222-9329 from non-development workstations, as the WebInjector module abuses CDP for browser manipulation.
Security Awareness
- Consider reinforcing awareness training about ClickFix social engineering attacks, where users are prompted to copy and paste shell commands from web pages to access content.
- Consider reminding users that legitimate websites will never ask them to execute PowerShell or command-line instructions to view content, and to report any such prompts immediately.
- If applicable, consider adding the ClickFix attack pattern to existing phishing awareness programs with specific examples of the 'copy and paste this command' social engineering technique.
MITRE ATT&CK Mapping
Persistence
Privilege Escalation
Stealth
Defense Impairment
Credential Access
Collection
Command and Control
Exfiltration
Additional IOCs
- Ips:
172[.]67[.]215[.]214- Cloudflare proxy IP observed hosting TELEPUZ staging URL (2026-06-24); limited actionability as shared CDN infrastructure172[.]67[.]165[.]144- Cloudflare proxy IP observed hosting TELEPUZ staging URL (2026-07-06); limited actionability as shared CDN infrastructure
- Domains:
chubrik[.]sbs- Early staging domain (2026-05-09) hosting TELEPUZ payload at randomized path /files/xK7mR9pL2nQw5tY8/ygvfuyze.dllbetalegenda[.]cfd- Staging domain (2026-05-14) hosting TELEPUZ payload at /files/xK7mR9pL2nQw5tY8/kmwvogwx.dllmavpaprokla[.]lat- Staging domain (2026-05-19) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllcomicstar[.]lat- Staging domain (2026-05-26) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllbigblower[.]click- Staging domain (2026-05-28) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllmomasites[.]lol- Staging domain (2026-06-05) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllmomasites[.]com- Staging domain (2026-06-07) hosting TELEPUZ payload at /files/telemetrywork/telepuzmamsites[.]lol- Staging domain (2026-06-07) hosting TELEPUZ payload at /files/telemetrywork/telepuz.dllhardenedom[.]shop- Staging domain (2026-06-07) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllhardendedom[.]shop- Staging domain (2026-06-07) hosting TELEPUZ payload at /files/lemetriawork/epuz.dllhardendom[.]shop- Staging domain (2026-06-08) hosting TELEPUZ payload at /files/telemetry/telepuz.dllhardeneddom[.]shop- Staging domain (2026-06-10) hosting TELEPUZ payload at /files/telemetrywork/telepuznetblokirovka[.]asia- Staging domain (2026-06-11) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllnetblokir[.]asia- Staging domain (2026-06-12) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllnetlobikrovka[.]asia- Staging domain (2026-06-14) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllneblokirovka[.]as- Staging domain (2026-06-15) hosting TELEPUZ payload at /telemetry/network/telepuz.dllkidsko[.]shop- Staging domain (2026-06-17) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllmazaporka[.]shop- Staging domain (2026-06-22) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllkrabsburger[.]xyz- Staging domain (2026-06-29) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dll via HTTPzewaplus[.]club- Staging domain (2026-06-30) hosting TELEPUZ payload at /files/telemetriawork/telepuz.dllcodebasecode[.]com- DNS-based fallback C2 resolver domain queried by malware; no DNS records found yet but malware is designed to extract and decrypt C2 from DNS responses
- Urls:
hxxps://memshowblob[.]forum/api/index.php?a=grab- First-stage URL downloaded by ClickFix PowerShell command to retrieve VIDAR second-stage payloadhxxps://t[.]me/chanadarkpart- Telegram profile used as dead drop resolver; contains XOR-encrypted fallback C2 URL (key: Goodman); channel created late April 2026hxxps://steamcommunity[.]com/profiles/76561199705801219- Steam profile used as dead drop resolver; profile name contains encrypted C2 address; name history reveals prior C2 domains
- File Hashes:
d0bba09f1bf9253816511731dd376e1cbbc8437c6225fda8b04c0bf1787236b9(SHA256) - First known TELEPUZ sample submitted to VirusTotal on May 2, 2026bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343(SHA256) - TELEPUZ main payload sampleff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e(SHA256) - TELEPUZ main payload samplea955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3(SHA256) - TELEPUZ keylogger module downloaded from C2 at /static/modules/kMP6HBGEA8.bin9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477eb(SHA256) - TELEPUZ stealer module downloaded from C2 at /static/modules/W2UMxylgG_.bin444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1(SHA256) - TELEPUZ webinjector module downloaded from C2 at /static/modules/yaVaoS3Bw.bin
- Registry Keys:
HKLM\SYSTEM\CurrentControlSet\Services\PilotmasterMast- Alternative Windows service persistence registry key used by some TELEPUZ samples
- File Paths:
%AppData%\Local\DCFG\Runtime\Themes\Processor\etwhost.dll- Persistence directory for TELEPUZ main payload; malware migrates here from %TEMP% and masquerades as telemetry host DLL%AppData%\Roaming\StateRepository\Host\Recovery\systemreset.dll- Alternative persistence path used by some TELEPUZ samples%AppData%\Local\MiravaDevices\noraxrecovery.dll- Alternative persistence path used by some TELEPUZ samples%ProgramData%\XeroxPrint\Temp\Worker\grpeng.dll- Installation directory for TELEPUZ main payload; stager writes the DLL here%ProgramData%\Jundrax\Tracker\IrenScanner.dll- Alternative installation path used by some TELEPUZ samples%ProgramData%\QualcommRF\dsp_agent.dll- Alternative installation path used by some TELEPUZ samples%AppData%\D3DSCache\amd64\SvcValidator.dll- Stager persistence path as observed in GetPathsInfo output
- Command Lines:
- Purpose: Download and execute VIDAR second-stage payload from staging domain via ClickFix social engineering | Tools:
PowerShell.exe,Net.WebClient| Stage: Initial Access |PowerShell.exe -NoP -w h -ep bypass -c - Purpose: Execute TELEPUZ main payload DLL with specified export name via rundll32 | Tools:
rundll32.exe| Stage: Execution |rundll32.exe <install_path>,<export_name>
- Purpose: Download and execute VIDAR second-stage payload from staging domain via ClickFix social engineering | Tools:
- Other:
bginfod_mtx- Additional mutex associated with TELEPUZ malware familywfj64_mtx- Additional mutex associated with TELEPUZ malware familyf322a5fa.exe- Filename of VIDAR second-stage payload downloaded to %TEMP% via ClickFix PowerShell commandCipherAllocator- Windows service name used by TELEPUZ for persistence; masquerades as legitimate softwarePilotmasterMast- Alternative Windows service name used by some TELEPUZ samples for persistence/static/modules/kMP6HBGEA8.bin- C2 URI path for downloading keylogger module — consistent across samples/static/modules/yaVaoS3Bw.bin- C2 URI path for downloading webinjector module — consistent across samples/static/modules/W2UMxylgG_.bin- C2 URI path for downloading stealer module — consistent across samples/static/assets/chromelevator.bin- C2 URI path for downloading Chrome cookie extraction module based on Chrome-App-Bound-Encryption-Decryption projecttelemetriawork- Significant URL path marker appearing in most staging URLs; searching this term on VirusTotal yields large number of associated stagers and payloads