MalwareBazaar Database

This page shows some basic information the YARA rule Foxveil_Loader_CtorCfg_Variant including corresponding malware samples.

Database Entry


YARA Rule:Foxveil_Loader_CtorCfg_Variant
Description:Foxveil macOS loader (ClickFix -> AMOS), quill generation without the padding segment: fat x86_64+arm64 linking CoreFoundation+libSystem+libc++ but importing nothing from CoreFoundation, with the loader's fixed import core (task_info/mach_task_self_ resolver, open/write/unlink/setenv/unsetenv run-time config file) in both slices inside a per-build random libc decoy import set
Firstseen:2026-09-28 00:19:32 UTC
Lastseen:2026-10-06 12:07:39 UTC
Sightings:3

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter