MalwareBazaar Database

This page shows some basic information the YARA rule Foxveil_Loader_EmptySeg_Variant including corresponding malware samples.

Database Entry


YARA Rule:Foxveil_Loader_EmptySeg_Variant
Description:Foxveil macOS loader (ClickFix -> AMOS), apph4/cc2 packer generation, resolver-agnostic: fat x86_64+arm64 linking only CoreFoundation+libSystem+libc++, plus one empty randomly-named LC_SEGMENT_64 per slice flagged SG_PROTECTED_VERSION_1 with zero vmsize/fileoff/filesize/prot/nsects
Firstseen:2026-09-23 16:25:54 UTC
Lastseen:never
Sightings:1

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter