HackRead

New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords


Cybersecurity researchers at Jamf Threat Labs have identified CloudSyncD, a previously undocumented macOS backdoor distributed through a malicious disk image disguised as a Zoom installer.

The malware’s custom artwork instructs users to bypass macOS Gatekeeper, a security feature that blocks unverified applications, by manually approving the software through System Settings.

This research, shared with Hackread.com, details how the malware tricks users into revealing their passwords and uses the credentials to launch the second stage on their Macs.

    Fake Authorization Prompt Conceals Password

    Once launched, the first-stage binary, app_installer, displays a fake authorization prompt asking users to enter their password. The malware validates the password against the local account using the macOS directory service utility dscl. A fake “Downloading Zoom…” window then appears.

    Image via Jamf Threat Lab

    Rather than sending the credential to attackers, the malware stores it in ~/.config/zoom/data.json, disguised as a normal application configuration file. It base64-encodes the password and hides it inside a cache string surrounded by random filler.

    Zero-width Unicode characters embedded in the adjacent version field encode the password’s location and length, making it difficult to identify. The password is then used to launch the embedded second-stage backdoor with sudo privileges.

      Backdoor Enables Further Remote Activity

      The dropper carries an approximately 756 KB universal Mach-O executable that runs on both Apple silicon and Intel-based Macs. It first attempts to launch the payload through /dev/fd without writing it to disk. This failed during Jamf’s testing, so the malware used mkstemp to create a temporary file before launching the backdoor.

      A temporary shell script also attempts to replace the original application bundle with another copy and then deletes itself. However, Jamf did not observe the application swap succeeding in its tested builds.

      The second stage is named cloudsyncd in its configuration and is designed to use a hidden path under the user’s home directory, according to Jamf’s blog post. It collects system information, including the hardware UUID, processor details, memory and device data, and sends a host survey to its command-and-control (C2) server. It then checks in every 8 to 16 seconds for further instructions, including executable files or compressed archives.

      From Testing to Live Infrastructure

      Jamf first identified a development build on September 15, 2026, and found versions configured to communicate with reachable C2 servers two days later. The malware uses URLs resembling jQuery JavaScript requests to make its network traffic appear more routine. The shift toward reachable infrastructure suggests the malware was moving beyond testing.

      Although the backdoor is designed for further remote activity, Jamf did not observe it establishing persistence during testing, such as through a LaunchAgent or LaunchDaemon.

      Jamf also noted that CloudSyncD lacks the built-in capabilities typically associated with infostealers, such as stealing browser data, Keychain items or cryptocurrency wallets. The findings show how familiar software can still be used as an effective lure for delivering native macOS malware.

      (Photo by Jonatas Nas)





Source link