INTEL_REPORT
The Hacker News · published 7/16/2026, 12:50:13 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs researcher Cyril François said in a technical report. "While the number of C2 [command-and-control] domains is currently small, the daily New TELEPUZ M…
https://thehackernews.com/2026/07/new-telepuz-malware-spreads-via.html
sha256:63f290c2492878095d2e778f90979fedb529190fe93aabd40a6fde5c1c85a148
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| wmiprvse.exe |
| Open → |
| domain | codebasecode.com | Open → |