BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Foxveil: Cloud-Native Loader Tradecraft on Cloudflar
 e\,\n   Netlify\, and Discord\n   Tags: Cloud Village | Creator Talk/Panel
 \n   When: Sunday\, Aug 9\, 11:50 - 12:30 PDT\n   Where: LVCCW Level 3 W31
 3 (Cloud Village Talks) - [1]Map\n\n   Description:\n\n   Malware loaders 
 used to advertise themselves with throwaway domains\,\n   fragile hosting\
 , and obvious command-and-control infrastructure.\n   Foxveil is a hard re
 set in loader tradecraft. Less attacker-owned\n   infrastructure\, less di
 sk-heavy execution\, fewer static clues\, and\n   more abuse of platforms 
 defenders see every day. This newly documented\n   loader stages payloads 
 from our most trusted and favorite cloud-native\n   tool chains: Cloudflar
 e Pages\, Netlify\, and Discord attachments\,\n   executes shellcode large
 ly in memory\, establishes persistence through\n   masqueraded Windows art
 ifacts\, and actively rewrites\n   analysis-significant strings at runtime
  to make reverse engineering\n   and static detection harder. Across two o
 bserved variants\, Foxveil\n   combines several pieces of modern tradecraf
 t into one compact\n   initial-stage loader. One variant spawns a fake svc
 host.exe and\n   performs Early Bird APC injection into the target process
  before it\n   fully resumes. Another pulls shellcode from Discord attachm
 ents and\n   executes it through self-injection. Both stage follow-on payl
 oads from\n   trusted platforms\, drop files into SysWOW64 under names des
 igned to\n   blend into normal Windows noise\, and use runtime string muta
 tion to\n   corrupt keywords such as beacon\, meterpreter\, shellcode\, an
 d even fox\n   itself. This talk walks through the full Foxveil infection 
 chain\, from\n   staging and shellcode delivery to persistence and follow-
 on\n   deployment\, and examines what makes this loader part of a broader\
 n   shift in attacker and malware tradecraft by comparing both variants.\n
    The real story is not just cloud-hosted staging. It is the emergence\n 
   of a loader model that borrows trust instead of building\n   infrastruct
 ure. Foxveil examines what modern initial-stage malware\n   looks like whe
 n it is designed for rotation\, ambiguity\, and survival.\n\n   Speakers:S
 hani Kurtzberg\,Zohar Buber\n\n   SpeakerBio:  Shani Kurtzberg\n\n   Shani
  Kurtzberg is an XDR Team Lead at Cato Networks and member of\n   Cato CTR
 L. She leads the Threat Intelligence and XDR Detection\n   Engineering ini
 tiatives. Prior to Cato\, Shani served in the Israeli\n   Air Force (IAF) 
 as a Security Analyst\, leading SOC operations to\n   protect critical sys
 tems. Shani holds a Master of Business\n   Administration (M.B.A.) from Pe
 res Academic Center\, specializing in\n   Marketing and Product Management
 .\n\n   SpeakerBio:  Zohar Buber\n\n   Zohar Buber is a security analyst i
 n Cato Research Labs at Cato\n   Networks. He focuses on network protocol 
 analysis and malicious\n   traffic detection\, specializing in threat iden
 tification using\n   network-based methods. He previously worked at Radwar
 e\, where he\n   examined threats in the DDoS industry. Zohar holds B.A fo
 cused in\n   Business Administration\, Information System Analysis // Zoha
 r Buber\,\n   zohar@devtalks.me\n\n   '\n\n   1. #LVCCW_Level3_South\n\n\n
DTEND:20260809T193000Z
DTSTART:20260809T185000Z
LOCATION:Cloud Village - LVCCW Level 3 W313 (Cloud Village Talks)
SUMMARY:Foxveil: Cloud-Native Loader Tradecraft on Cloudflare\, Netlify\, a
 nd Discord
END:VEVENT
END:VCALENDAR
