A macOS threat described by Jamf researchers targets users through a fake Zoom Mac installer that actually delivers a backdoor named CloudSyncD. The infection begins with social engineering to persuade the user to download what appears to be Zoom, but the downloaded disk image mounts as a volume named Zoom. The dropper inside this image contains the CloudSyncD payload and must be activated by the user, at which point it installs the backdoor rather than Zoom.
The dropper carries a complete universal Mach-O inside itself—around 756 KB in the development build—and also stores the payload on disk within the application bundle, giving two sources for execution.
Once activated, CloudSyncD operates as a persistent backdoor, performing host reconnaissance and exfiltrating system and user details to its C2. The payload is encrypted in the binary and decrypted at runtime, with a daemon named CloudSyncD handling the ongoing operations.
In early samples the C2 address was on a private network and verbose debugging remained enabled; more recently, multiple builds have appeared on two domains behind Cloudflare, masquerading as a jQuery script so beacon traffic appears as ordinary JavaScript fetch requests. The researchers note a high degree of similarity across builds, including the same string obfuscation table, install paths, daemon name, process disguise, and the same C2 key and IV, differing only by endpoint.
The malware obtains root privileges by using the phished password locally to execute the backdoor, rather than exfiltrating it. Security teams are urged to monitor the published IOCs as the campaign has progressed to deployment.