[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKHIt47H4yY8VMel-lyKcd9n4w1WYrqDcBFwJoDVi1I0":3},{"article":4,"iocs":46},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"b3e39fad-bd66-4d48-9a10-9fe952969ebb","macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor","macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor-174e76","The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek.","A new macOS backdoor, dubbed CloudSyncD, has been observed evolving from development to active deployment. Disguised as a legitimate Zoom installer, the malware uses social engineering to trick users into granting it elevated privileges, bypassing macOS System Integrity Protection. Once installed, CloudSyncD establishes a persistent, stealthy backdoor for long-term access and reconnaissance.","macOS users targeted by fake Zoom installer delivering CloudSyncD backdoor.","A macOS dropper has been found inside a disguised Zoom client. The malware is tracked as CloudSyncD and is designed to deliver a persistent and stealthy backdoor. Researchers at Jamf first noticed this malware still in development in mid-September. Within days, other samples were found suggesting it has now progressed from testing and development to deployment. The malware infection process is initiated by any of the standard social engineering methods designed to persuade or trick victims into downloading dangerous content. In this case it is malware hidden in malicious code disguised as a Zoom Mac installer. If the phish is successful, a malware dropper is delivered to the victim as a disk image that mounts as a volume named Zoom. This dropper contains the payload but must be activated by the victim – hence the disguise as a Zoom installer. The victim is guided through the activation thinking it will install Zoom, but it actually installs CloudSyncD. The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The same payload is also present on disk inside the application bundle, so the dropper has two sources for it,” say the researchers. The payload is written to an anonymous file descriptor, and the dropper attempts to execute it. Execution will fail in most cases because of the MacOS System Integrity Protection. If so, the dropper writes the file temporarily to disk and executes it using sudo along with the user’s password collected during the activation process. The result of successful activation is implementation of the CloudSyncD malware. Its configuration is stored encrypted in the binary and decrypted at runtime. It runs through a daemon named CloudSyncD. The malware first analyzed by the researchers had not reached deployment stage. The C2 address was on a private network, and verbose debug logging was left on.Advertisement. Scroll to continue reading. Now, however, the researchers have seen several malware builds on two separate domains. The URI path is identical in both, masquerading as a jQuery script so a beacon resembles an ordinary JavaScript fetch. Both domains were registered in 2011 through the same registrar and sit behind Cloudflare, and neither carried any detections at the time of writing. “Every build shares the same string obfuscation table, the same install paths, daemon name and process disguise, and, more tellingly, the same C2 key and initialization vector, down to the identical per-string seeds,” say the researchers. “Only the endpoint changes. Captured beacon traffic is therefore decryptable with material recovered from any build, and the on-host indicators hold across all of them.” This discovery and analysis of new malware from development to deployment demonstrates how macOS malware continues to move toward native implementations, string protection, and execution paths that attempt to avoid writing payloads to disk – while still depending on the oldest attacker technique available: socially engineering victims to hand over their password. CloudSyncD serves as a persistent backdoor designed to establish stealthy, long-term access to the infected Mac allowing attackers to deploy follow-up payloads. It conducts host profiling and reconnaissance and exfiltrates system and user details to its C2. It appears in initial delivery process to be similar to an infostealer, but this is not an infostealer in function. It contains no standard infostealer information-stealing functionality. The phished user password, for example, is not exfiltrated but solely used locally to grant root privileges for executing the ongoing backdoor. Since the malware has now reached deployment, the researchers also provide a long list of IOCs to monitor. Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Related: Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates Related: Recent macOS Screen Sharing Vulnerability Exploited in Attacks Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral CompassDARPA Selects Xint to Use AI in Securing Military Messaging AppsRig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity RisksModulate Raises $25 Million to Advance Deepfake DetectionIonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderOuterlimit Raises $16 Million to Stop Rogue AI Agents From Causing HarmCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastRansomware Attacks on Manufacturers Surge as Supply Chain Risk Grows Latest News Crypto Scammers Hijack Microsoft’s Official X AccountIn Rare Move, Alleged Iranian State Hacker Extradited to USWarlock Expands SharePoint Exploitation in Critical Infrastructure AttacksAI Agents Aimed SQL Injection at US and Canadian Government SitesExploited Fortinet FortiMail Zero-Day Calls for Urgent ActionZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksOsavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical DomainsEnterprises Struggle to Prepare for AI and Quantum Threats, PwC Says Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fmacos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F01\u002FCybersecurity_News-SecurityWeek.jpg","2026-10-02T13:15:00+00:00","2026-10-02T14:01:09.996816+00:00",8,[18,21,23,26],{"name":19,"type":20},"macOS","product",{"name":22,"type":20},"Zoom",{"name":24,"type":25},"Mach-O","technology",{"name":27,"type":25},"System Integrity Protection","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":28,"icon":30,"name":31,"slug":32},null,"Malware","malware",[34,39,41],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":40},{"id":28,"icon":30,"name":31,"slug":32},{"category":42},{"id":43,"icon":30,"name":44,"slug":45},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[47,51,53,57,60,63],{"type":48,"value":49,"context":50},"domain","cloudsyncd.com","Command and Control (C2) domain",{"type":48,"value":52,"context":50},"cloudsyncd.net",{"type":54,"value":55,"context":56},"mitre_attack","T1059.004","Command and Scripting Interpreter: Unix Shell",{"type":54,"value":58,"context":59},"T1547.001","Boot or Logon Autostart Execution: Registry Run Keys \u002F Startup Folder",{"type":54,"value":61,"context":62},"T1071.001","Application Layer Protocol: Web Protocols",{"type":54,"value":64,"context":65},"T1027","Obfuscated Files or Information"]