New TELEPUZ Malware Leveraging ClickFix Lures to Steal Data and Execute Commands
What Happened — Researchers at Elastic Security Labs identified a modular malware family named TELEPUZ that has been distributed since late April 2026 through compromised websites that host “ClickFix” lure pages. The payload can exfiltrate files, capture credentials, and execute arbitrary commands via a small set of command‑and‑control (C2) domains.
Why It Matters for Compliance & Audit Readiness
- The campaign illustrates a classic phishing‑style drive‑by attack that bypasses perimeter defenses, a scenario SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) controls are designed to detect and log.
- Continuous evidence of web‑asset monitoring and employee security‑awareness training provides the audit trail needed to demonstrate due diligence.
- Leveraging Verisq’s Security Awareness Training capability helps embed the required policies and measurable training metrics into your SOC 2 evidence package.
Who Is Affected — Technology‑SaaS providers, financial services firms, and any organization that hosts public‑facing web applications or relies on third‑party content delivery.
Recommended Actions
- Map the incident to SOC 2 CC6.1 (Access Controls) and CC7.1 (System Operations) and begin collecting logs from web servers, WAFs, and endpoint protection tools.
- Deploy or refresh security‑awareness training that covers malicious‑link identification, safe browsing, and reporting procedures.
- Implement continuous monitoring of external web assets for unauthorized script injections or lure pages.
Source: The Hacker News
Technical Notes — TELEPUZ is a lightweight, modular framework; its C2 infrastructure is limited but actively expanded. It uses standard HTTP(S) for command delivery, supports data exfiltration via encrypted uploads, and can execute PowerShell or Bash commands on compromised hosts. No specific CVE is associated. Source: Elastic Security Labs technical report