Advanced Web Injection Module Expands TELEPUZ Malware Capabilities

Security researchers have uncovered a powerful web injection module used by the TELEPUZ malware family that enables attackers to manipulate banking sessions, steal browser data, execute malicious JavaScript, and modify financial transactions in real time.


According to researchers, the module is part of the rapidly evolving TELEPUZ malware-as-a-service (MaaS) platform, which has been spreading through ClickFix social engineering campaigns since April 2026. The latest component significantly expands the malware's credential theft and financial fraud capabilities.


Browser Sessions Hijacked in Real Time

Once installed, the web injector monitors browser activity and injects malicious JavaScript into targeted websites while victims browse normally.


This allows attackers to alter webpage content, capture login credentials, intercept authentication data, and manipulate user interactions without raising suspicion. Researchers noted that the injections occur directly within legitimate browser sessions, making detection considerably more difficult.


Banking Transactions Can Be Manipulated

One of the module's most dangerous features is its ability to replace IBAN account numbers during online banking transactions.
By silently substituting legitimate beneficiary details with attacker-controlled accounts, the malware can redirect financial transfers without the victim noticing. The injector can also steal browser cookies, session tokens, and sensitive credentials to facilitate account takeover attacks.


Malware Includes Broad Remote Control Features

Beyond web injection, TELEPUZ provides attackers with an extensive set of post-compromise capabilities, including:


- Remote command execution.
- Browser cookie theft.
- JavaScript execution inside browser sessions.
- File management and data exfiltration.
- Keystroke logging.
- Persistent remote access.


Researchers also observed multiple anti-analysis techniques, including anti-debugging, anti-virtual machine checks, and defense evasion mechanisms designed to avoid detection by security tools.


Resilient Command Infrastructure

TELEPUZ maintains communication with its operators through several fallback mechanisms, including Telegram, Steam profiles, DNS records, and Polygon blockchain smart contracts.
This multi-layered command-and-control architecture allows attackers to recover infrastructure even if primary servers are disrupted, increasing the malware's resilience against takedown efforts.


Organizations Should Strengthen Browser Security

Researchers recommend that organizations train employees to recognize ClickFix social engineering attacks, monitor suspicious PowerShell activity, restrict unauthorized script execution, and deploy endpoint detection tools capable of identifying browser injection techniques.


As TELEPUZ continues to evolve, defenders should also monitor for unusual browser modifications, credential theft activity, and unauthorized financial transaction changes that may indicate active web injection attacks.