Malware · 10h ago

CloudSyncD Poses as Zoom to Unlock Mac Backdoor

Jamf Threat Labs found CloudSyncD, a macOS backdoor disguised as a Zoom installer, moving from under-development samples on September 15 to samples tied to live command-and-control infrastructure two days later. Jamf said it found no confirmed infections, but the tooling had clearly shifted from testing toward deployment.

The installer tricks users into bypassing macOS protections, then shows a fake authorization prompt that checks the entered password locally. That password is not stolen for reuse; it is used to launch a second-stage payload with elevated privileges, so the prompt is part of the execution path, not a credential-theft event.

For macOS defenders and help desks, the operational change matters more than the lure itself: a fake installer can now deliver a privileged second stage without obvious network exfiltration. If this kind of sample reaches users in your environment, password-prompt telemetry alone will not tell the full story.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-10-02

Editions

Related stories