JAMF Threat Labs uncovered CloudSyncD, a macOS backdoor hidden inside a fake Zoom installer. The malicious package presents as a user-facing macOS installer, with the disk image mounted as a volume named Zoom and an Applications shortcut. It guides the user to bypass Gatekeeper by claiming the app is ad-hoc signed. When the fake installer runs, a password prompt appears repeatedly, allegedly to proceed with installation.
The analysis notes the dropper validates the entered password against the local account using dscl and only proceeds if the check succeeds, before showing a fake “Downloading Zoom…” progress window. The captured password is not immediately exfiltrated; it is encoded in base64, padded with filler, and hidden inside a data[.]json-like settings file, with 48 invisible Unicode characters following the version to indicate the password’s start and length. The technique allows the password to be concealed within what looks like legitimate preferences.
The payload inside the dropper is a universal Mach-O file (about 756 KB in the development build) that can run from memory via an anonymous file descriptor, but System Integrity Protection blocks this on most Macs. When the in-memory execution fails, the dropper writes the payload to a temporary file and runs it with sudo using the stolen password.
The second stage, named cloudsyncd, creates a working directory, logs activity with encrypted records, and pings a remote server every 8–16 seconds, carrying a hardware identifier. The server can return either a compressed archive to unpack or a full executable to run, enabling delivery of new components beyond individual commands. By the time of reporting, CloudSyncD was already contacting two live domains protected by Cloudflare, with samples sharing the same encryption key and IV.