MalwareBazaar Database
This page shows some basic information the YARA rule Foxveil_Loader_CtorCfg_Variant including corresponding malware samples.
Database Entry
| YARA Rule: | Foxveil_Loader_CtorCfg_Variant |
|---|---|
| Description: | Foxveil macOS loader (ClickFix -> AMOS), quill generation without the padding segment: fat x86_64+arm64 linking CoreFoundation+libSystem+libc++ but importing nothing from CoreFoundation, with the loader's fixed import core (task_info/mach_task_self_ resolver, open/write/unlink/setenv/unsetenv run-time config file) in both slices inside a per-build random libc decoy import set |
| Firstseen: | 2026-09-28 00:19:32 UTC |
| Lastseen: | 2026-10-06 12:07:39 UTC |
| Sightings: | 3 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|