A newly discovered macOS backdoor dubbed CloudSyncD is being distributed through a fake Zoom installer that guides victims into disabling Apple’s Gatekeeper protections and handing over their login passwords.[1][2][11] Researchers at Jamf Threat Labs say the malware arrives as a malicious disk image styled to look like a legitimate Zoom client, but instead launches a two-stage backdoor designed for stealthy, long-term access to compromised Macs.[2][3] The campaign shows that threat actors are increasingly abusing familiar brands and user interface conventions to turn routine software installs into high‑impact compromises without exploiting a traditional vulnerability.[1][3]
The fake installer mounts as a volume named “Zoom” and uses custom background artwork with numbered steps instructing users to open System Settings, navigate to Privacy & Security, click “Open Anyway,” and approve the unsigned app, effectively walking them around Gatekeeper’s default protections.[2][8][11] Once launched, the first‑stage binary, often referred to as app_installer, displays a counterfeit macOS authorization prompt and repeatedly requests the user’s password until valid credentials are supplied, checking them against the local account with directory service tools.[2][4][10] Jamf’s analysis notes that the dropper embeds a complete universal Mach‑O payload of roughly 756 KB in development builds, extracting and executing it at runtime with sudo to gain elevated privileges on both Intel and Apple silicon systems.[1][2][10] The stolen password is then concealed inside a seemingly benign configuration file using invisible Unicode characters, allowing operators to hide sensitive credentials in plain sight while avoiding casual inspection.[2][10][13]
CloudSyncD’s second stage is configured to install a persistent backdoor under a hidden path in the user’s home directory, enabling attackers to maintain access and launch follow‑up payloads long after the bogus Zoom setup appears to complete.[2][5] In many observed samples, the installer does deploy a working copy of Zoom, helping the ruse blend in and reducing the chance that users notice anything unusual after installation.[9][11] The backdoor can record user‑entered data and transmit it to remote command‑and‑control infrastructure as frequently as every eight seconds, effectively functioning as an infostealer with remote command execution capabilities.[5][9][11] Security researchers report that recent samples are configured against live C2 servers, indicating the malware has moved beyond development testing into active use against macOS users.[3][5]
Current reporting does not tie CloudSyncD to a specific threat group, and there is no evidence that it relies on a documented Zoom or macOS vulnerability, meaning there are no associated CVE entries or vendor patches to apply at this time.[1][2][3] Instead, the infection chain hinges on social engineering, abusing user trust in the Zoom brand and Apple’s interface to convince victims to override security warnings and supply their system password.[2][8][11] Samples were first spotted during routine monitoring of uploads to VirusTotal and have since been discussed by multiple security outlets, suggesting at least limited circulation in the wild, though the full scale of deployment remains unclear.[1][5][10] Because the backdoor operates under the user’s own credentials and can run with elevated privileges, a successful compromise effectively gives attackers broad control over the affected Mac, including access to sensitive data and potential lateral movement inside corporate environments.[2][5][9]
Defenders have limited recourse beyond hardening user behavior and tightening controls around application installation, but several practical steps can reduce exposure to CloudSyncD and similar threats.[2][8][11] Organizations should reinforce policies that restrict macOS users to software obtained from the official Mac App Store or trusted vendor download portals and warn employees never to bypass Gatekeeper for unexpected installers, even when they appear branded as popular apps.[8][11] Endpoint and EDR teams can hunt for disk images that mount as “Zoom” but lack a valid developer signature, repeated sudo invocations from unsigned installers, unusual use of dscl for password validation, and unknown universal Mach‑O binaries spawning outbound network connections.[2][4][10] Users who suspect they may have run a fake Zoom installer should immediately change their Mac login password, enable multi‑factor authentication wherever possible, and work with security teams to scan for persistence mechanisms or data exfiltration consistent with CloudSyncD.[2][5][9]
References
- macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
- CloudSyncD: macOS backdoor hidden in a fake Zoom …
- CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
- Fake Zoom installer delivers new CloudSyncD macOS backdoor
- CloudSyncD macOS backdoor uses a fake Zoom installer to steal …
- Fake Zoom installer tricks Mac users into bypassing …
- New macOS malware masquerades as Zoom installer
- CloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords in Plain Sight
- This fake Mac Zoom installer has a sneaky way to bypass …
- Dark Web Intelligence on X: ” NEW MACOS BACKDOOR HIDES …