Malware · 10h ago
Jamf Threat Labs found CloudSyncD, a macOS backdoor disguised as a Zoom installer, moving from under-development samples on September 15 to samples tied to live command-and-control infrastructure two days later. Jamf said it found no confirmed infections, but the tooling had clearly shifted from testing toward deployment.
The installer tricks users into bypassing macOS protections, then shows a fake authorization prompt that checks the entered password locally. That password is not stolen for reuse; it is used to launch a second-stage payload with elevated privileges, so the prompt is part of the execution path, not a credential-theft event.
For macOS defenders and help desks, the operational change matters more than the lure itself: a fake installer can now deliver a privileged second stage without obvious network exfiltration. If this kind of sample reaches users in your environment, password-prompt telemetry alone will not tell the full story.
2 sources covering this story
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor
Part of the PlainSec briefing for 2026-10-02