www.infosecurity-magazine.com 1 Oct 2026, 13:30 UTC

Fake Zoom Installer Hides CloudSyncD Backdoor Behind Password Prompt

CyberSIXT Evidence Panel Source marked as original reporting

A new macOS backdoor, dubbed CloudSyncD, has been found hidden inside a fake Zoom installer that asks users to enter their login password before launching a second-stage payload. Jamf Threat Labs first observed CloudSyncD on 15 September in a development build, and by 30 September samples were configured to connect to live command-and-control infrastructure across multiple domains, indicating progression toward deployment.

The malware arrives as a disk image masquerading as a legitimate Zoom installer and instructs users to override macOS security protections via the System Settings to bypass Gatekeeper, then presents a fake authorization prompt.

The password supplied by the user is not exfiltrated; instead CloudSyncD hides it in a decoy configuration file using zero-width Unicode characters. The collected password is used to start the second stage with elevated privileges, with the embedded payload implemented as a universal Mach-O binary compatible with both Apple silicon and Intel Macs.

CloudSyncD attempts to execute the payload through /dev/fd to avoid writing the binary to disk; if that fails, it temporarily writes the payload and launches it via sudo using the harvested password. The implant establishes a hidden directory under the user’s home folder named cloudsyncd and communicates with a C2 server using encrypted traffic. Initial checks gather system information, followed by subsequent check-ins that transmit hardware identifiers.

Jamf notes that CloudSyncD appears to be a backdoor rather than a conventional information stealer, with remote task execution capabilities but no observed persistence or confirmation of infections to date. No confirmed infections were reported, and the activity was identified through VirusTotal monitoring.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline