Socprime
Foxveil Malware Loader Exploits Discord, Cloudflare, and Netlify for Payload Staging
First seen 14 Feb 2026, 03:09 UTC
•


•82% similarity
•36.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Foxveil is a newly identified malware loader first detected in August 2025. It utilizes legitimate platforms such as Discord, Cloudflare, and Netlify to stage Donut-generated shellcode, employing techniques like in-memory execution and process injection for evasion. The loader can achieve persistence by registering a Windows service or modifying Microsoft Defender settings.
ThreatCluster AI
Timeline
2025-08-01
Foxveil malware loader first detected
2026-02-12
Cato Networks reports on Foxveil's activities
2026-02-14
Socprime publishes detailed analysis of Foxveil