Skip to main content
Emerging ThreatsMalware & Ransomware

CloudSyncD Backdoor Exploits Zoom Installer to Infiltrate MacOS Systems

MacBook on cluttered desk with partially opened Zoom installer on screen.

"The password is never sent anywhere," Jamf said.

Discovery timeline: testing to live C2 in days

Jamf Threat Labs first encountered the malware now called CloudSyncD on September 15 in a build the company described as still under development. Two days later, on September 17, Jamf found samples that were configured against live command-and-control (C2) infrastructure across more than one domain, signaling that the operation had progressed toward deployment. Jamf published its research on September 30 and reported that it found the program through VirusTotal monitoring; Jamf did not report any confirmed infections.

How CloudSyncD masquerades as a Zoom installer

The malware is distributed as a disk image crafted to resemble a legitimate Zoom installer. The dropper instructs users to override macOS security protections through the System Settings interface, explicitly guiding victims around Gatekeeper. As part of the installation flow, the fake installer displays an authorization prompt that requests the user's login password.

Password capture, local validation, and concealment

Jamf's analysis found that the installer validates the supplied password against the local account and does not transmit it externally. Instead, the captured credential is buried in a decoy configuration file; the malware uses zero-width Unicode characters to mark where the password sits inside that file. According to Jamf, the password is used to launch a second-stage payload with elevated privileges rather than being harvested for credential theft.

Second-stage execution techniques and payload behavior

The embedded second-stage payload is a universal Mach-O binary supporting both Apple silicon and Intel Macs. CloudSyncD attempts to execute this payload through /dev/fd to avoid writing the binary to disk. When that approach failed during Jamf's testing, the malware wrote the payload temporarily and launched it using sudo with the harvested password. The implant creates a hidden working directory under the user's home folder and is configured to operate under the name cloudsyncd.

C2 communications, capabilities, and limits observed

CloudSyncD communicates with its operator using encrypted traffic. On first contact it sends a host survey containing system information; subsequent check-ins carry the machine's hardware identifier. Jamf described the implant as a backdoor rather than a conventional infostealer: it lacked built-in routines for collecting browser data, Keychain items, or cryptocurrency wallets. The implant does provide a remote task execution capability that allows an operator to deliver executable files or compressed archives for execution.

During Jamf's analysis the researchers did not observe persistence and did not see the implant install itself as cloudsyncd — a step Jamf said was not reached because no remote task was delivered during the investigation.

What this means for technologists, end users, and enterprises

  • Technologists and security teams: Watch for disk-image installers that prompt for login credentials and explicitly guide users to bypass macOS Gatekeeper. Note the use of in-memory or temporary execution techniques — attempts to run binaries from /dev/fd and fallback to temporary disk writes with sudo were observed.
  • End users and the general public: Be alert to installers that request your account password and to prompts that instruct you to change System Settings to permit execution; Jamf found that the captured password was validated locally and not transmitted off-device, but it was then used to escalate and run a second-stage payload.
  • Affected enterprises and procurement leaders: The operation demonstrates a staged delivery model that can move quickly from testing to live C2; Jamf found development samples on September 15 and samples configured for live infrastructure by September 17. Procurement and endpoint teams should account for the possibility of disguised disk images and review controls around installation of unsigned software.

CloudSyncD's design is notable for what it does and does not do: it buries a locally validated password in a decoy file using zero-width Unicode markers, then uses that credential to run a universal Mach-O second stage without initial on-disk persistence in some cases. Jamf's findings stop short of witnessed deployment activity — the researchers did not observe a delivered task or confirmed infections — but the rapid movement from a test build to samples tied to live C2 infrastructure underscores an operation that has moved beyond proof-of-concept. Whether operators push tasks that enable persistence and broader data collection remains an open operational question tied to future observations.

Original reporting: https://www.infosecurity-magazine.com/news/cloudsyncd-macos-backdoor-fake/