
TELEPUZ: The Modular Malware Using Telegram, Steam, and a Blockchain to Phone Home
TELEPUZ is a newly discovered modular malware written in C that has been spreading since late April 2026 through ClickFix-style social engineering attacks, which trick users into pasting and executing malicious commands. Once installed, it employs extensive evasion techniques — including anti-VM checks, AMSI/ETW disabling, and obfuscation — before establishing contact with its command-and-control server via WebSockets to steal data, log keystrokes, capture screenshots, and execute commands. The malware uses multiple fallback methods to locate its C2 server, including Telegram, Steam, DNS queries, and a Polygon blockchain smart contract, and is believed to be an early-stage malware-as-a-service (MaaS) offering based on its high build volume and rapid development pace.
21 Jul 2026