MalwareOct 1, 2026
New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
New macOS backdoor CloudSyncD uses fake Zoom installer to steal passwords.
Summary
A new macOS backdoor, dubbed CloudSyncD, has been discovered distributing itself via a fake Zoom installer. This malware is designed to steal user passwords and bypass macOS's Gatekeeper security feature. Once infected, devices are connected to command-and-control (C2) servers, allowing attackers to maintain persistent access and exfiltrate sensitive data.
Indicators of Compromise
- malware — CloudSyncD
Entities
macOS (product)Zoom (product)Gatekeeper (technology)