TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
Elastic Security Labs discovered TELEPUZ, a modular malware-as-a-service (MaaS) platform actively spreading via CLICKFIX-VIDAR social engineering chains since April 2026. The malware employs sophisticated evasion techniques including indirect syscalls, AMSI/ETW patching, NTDLL unhooking, and UAC bypass via COM elevation and AppInfo ALPC. Command & control infrastructure uses WebSockets with fallback mechanisms via Telegram, Steam profiles, DNS records, and Polygon blockchain smart contracts.