Cato CTRL reported a previously undocumented malware loader dubbed Foxveil that abuses legitimate services—Cloudflare Pages, Netlify, and short-lived Discord attachments—to stage and retrieve next-stage payloads while blending into normal cloud traffic. The campaign has been assessed as active since August 2025 and uses Donut-generated shellcode with in-memory execution to reduce on-disk artifacts; it also employs a string-mutation routine that rewrites “high-signal” analysis keywords (e.g., payload, inject, shellcode, beacon, http://, .exe) at runtime to complicate static detection and reverse engineering.
Two variants were described. Foxveil v1 retrieves payloads from Cloudflare/Netlify, spawns a process impersonating svchost.exe, and injects code using Early Bird APC injection (queuing the APC while the target process is suspended), then establishes persistence by registering as a Windows service; Foxveil v2 instead performs self-injection and was observed attempting to manipulate Microsoft Defender settings, but appears to mistakenly remove (rather than add) an exclusion for the SysWOW64 path. Both variants drop next-stage payloads into SysWOW64, and Cato reported the malicious staging infrastructure to providers—Netlify confirmed takedown of reported URLs (Jan 19, 2026) and Cloudflare restricted access to reported URLs (Jan 20, 2026)—while Discord attachment links observed were no longer active due to their time-limited nature; Cato also noted potential follow-on use of frameworks such as Cobalt Strike.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Cato Networks published research on Foxveil, describing two variants, Donut-generated shellcode, in-memory execution, string mutation, process injection techniques, and persistence behavior. The disclosure also included detection guidance focused on suspicious process chains, staged downloads, and writes to system directories.
After Cato reported Foxveil-related malicious infrastructure, Cloudflare and Netlify took action against it in January 2026. Discord-based staging links observed by researchers had already expired because the attachment URLs were short-lived.
Cato Networks assessed that the Foxveil malware loader had been active since August 2025. The loader used legitimate services including Discord, Cloudflare, and Netlify to stage and retrieve payloads while blending into normal traffic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.