# TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

DevFeed: [TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains](<https://devfeed.tech/articles/telepuz-a-modular-maas-malware-spreading-via-clickfix-vidar-chains-49118.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/threat-command/telepuz-maas-malware-clickfix>)

Author: Cyril François

Published: 2026-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [C2](<https://devfeed.tech/topics/c2.md>), [WebSocket](<https://devfeed.tech/topics/websocket.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [c2](<https://devfeed.tech/tags/c2.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [development](<https://devfeed.tech/tags/development.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [go](<https://devfeed.tech/tags/go.md>), [infection](<https://devfeed.tech/tags/infection.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-analysis](<https://devfeed.tech/tags/malware-analysis.md>), [modular](<https://devfeed.tech/tags/modular.md>), [payload](<https://devfeed.tech/tags/payload.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [staging](<https://devfeed.tech/tags/staging.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [websockets](<https://devfeed.tech/tags/websockets.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

Elastic Security Labs analyzes TELEPUZ, a modular malware family distributed through CLICKFIX-VIDAR infection chains. The report describes its staged delivery, PowerShell execution, Go-based VIDAR variant, WebSocket communication, payload modules, and signs of active development.

## Source excerpt

TELEPUZ is a modular malware that emerged through CLICKFIX-VIDAR attacks in April. We reverse-engineered it to show you the infrastructure and evasion techniques that matter.