Back to Feed
MalwareOct 1, 2026

New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords

New macOS backdoor CloudSyncD uses fake Zoom installer to steal passwords.

Summary

A new macOS backdoor, dubbed CloudSyncD, has been discovered distributing itself via a fake Zoom installer. This malware is designed to steal user passwords and bypass macOS's Gatekeeper security feature. Once infected, devices are connected to command-and-control (C2) servers, allowing attackers to maintain persistent access and exfiltrate sensitive data.

Indicators of Compromise

  • malware — CloudSyncD

Entities

macOS (product)Zoom (product)Gatekeeper (technology)