Foxveil Malware Loader Exploits Discord, Cloudflare, and Netlify for Payload Staging

Foxveil Malware Loader Exploits Discord, Cloudflare, and Netlify for Payload Staging

First seen 14 Feb 2026, 03:09 UTC ScmagazineSocprimeGbhackersCybersecuritynews 82% similarity 36.9

Article Content

Browse articles
ThreatCluster

Foxveil is a newly identified malware loader first detected in August 2025. It utilizes legitimate platforms such as Discord, Cloudflare, and Netlify to stage Donut-generated shellcode, employing techniques like in-memory execution and process injection for evasion. The loader can achieve persistence by registering a Windows service or modifying Microsoft Defender settings.

ThreatCluster AI

Timeline

2025-08-01
Foxveil malware loader first detected
2026-02-12
Cato Networks reports on Foxveil's activities
2026-02-14
Socprime publishes detailed analysis of Foxveil

Community

Browse all →