VYPR
researchPublished Oct 1, 2026· 2 sources

CloudSyncD Backdoor Disguised as Zoom Installer Targets macOS Users

A new macOS backdoor, CloudSyncD, is being distributed through a fake Zoom installer that tricks users into granting elevated privileges.

A sophisticated new backdoor, identified as CloudSyncD, has emerged targeting macOS users by masquerading as a legitimate Zoom installer. Security researchers at Jamf Threat Labs first observed the malware in development stages on September 15th, and by September 17th, they detected samples actively communicating with command-and-control (C2) infrastructure, indicating a transition from testing to active deployment.

The distribution method involves a disk image file designed to mimic the official Zoom installer. Upon execution, the malware guides users through a process that bypasses macOS's Gatekeeper security features by instructing them to adjust settings in the System Settings interface. This social engineering tactic aims to lower user defenses before the malicious payload is delivered.

Once past initial security hurdles, the fake installer presents a seemingly innocuous authorization prompt, requesting the user's local account password. Crucially, the malware does not exfiltrate this password. Instead, it uses the provided credentials to gain elevated privileges and then buries the password within a decoy configuration file, cleverly marking its location using zero-width Unicode characters.

The primary objective of CloudSyncD appears to be establishing a persistent backdoor rather than acting as a traditional information-stealer. Analysis revealed that the malware did not contain modules for harvesting browser data, Keychain items, or cryptocurrency wallets. The captured password's sole purpose was to facilitate the execution of a second-stage payload with administrative rights.

This second stage is delivered as a universal Mach-O binary, compatible with both Apple Silicon and Intel-based Macs. The backdoor attempts to execute this payload stealthily using the /dev/fd mechanism to avoid writing the binary directly to disk. If this method fails, it resorts to temporarily writing the payload and executing it with the previously obtained administrative password via sudo.

CloudSyncD establishes a hidden working directory within the user's home folder and communicates with its C2 servers using encrypted traffic. The initial communication includes a survey of system information, followed by subsequent check-ins that transmit the machine's hardware identifier. While Jamf did not observe persistence mechanisms being installed during their analysis, the implant's remote task execution capabilities suggest operators could deploy further malicious files or archives.

Although the malware was found configured against live C2 infrastructure, Jamf has not reported any confirmed infections to date. The discovery highlights the persistent threat of sophisticated malware targeting the macOS ecosystem, often leveraging social engineering and deceptive installer packages to compromise user systems.

This new report details the technical execution of the CloudSyncD backdoor, including its two-stage infection process and how it leverages a fake authorization prompt to capture administrator passwords. Researchers observed the malware communicating with command servers and noted its ability to download and execute additional payloads, though persistence mechanisms were not yet observed in the analyzed samples. The analysis also highlights specific indicators of compromise, such as unique character sequences within settings files used to identify the backdoor's payload.

Synthesized by Vypr AI