MalwareBazaar Database

This page shows some basic information the YARA rule Foxveil_Loader_TaskInfo_Variant including corresponding malware samples.

Database Entry


YARA Rule:Foxveil_Loader_TaskInfo_Variant
Description:Foxveil macOS loader (ClickFix -> AMOS), quill generation with run-time settings back inside the payload script (no constructor settings file): fat x86_64+arm64 linking CoreFoundation+libSystem+libc++ but importing nothing from CoreFoundation or objc, with the task_info/mach_task_self_ resolver core in both slices inside a per-build random libc decoy import set
Firstseen:2026-10-01 00:54:34 UTC
Lastseen:2026-10-03 00:03:25 UTC
Sightings:6

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter