[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-DjzE4fUCIXvTuZmEMDJaQtE_s_bFhDHGGRBsgMo4zM":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":25,"category":26,"article_tags":29},"20120642-10fb-4e5b-98bc-1b9b6892b38e","New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords","new-cloudsyncd-macos-backdoor-uses-fake-zoom-installer-to-steal-passwords-e05d9b","CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers.","A new macOS backdoor, dubbed CloudSyncD, has been discovered distributing itself via a fake Zoom installer. This malware is designed to steal user passwords and bypass macOS's Gatekeeper security feature. Once infected, devices are connected to command-and-control (C2) servers, allowing attackers to maintain persistent access and exfiltrate sensitive data.","New macOS backdoor CloudSyncD uses fake Zoom installer to steal passwords.",null,"https:\u002F\u002Fhackread.com\u002Fcloudsyncd-macos-backdoor-fake-zoom-installer-passwords\u002F","2026-10-01T15:36:17+00:00","2026-10-01T16:00:25.273731+00:00",8,[17,20,22],{"name":18,"type":19},"macOS","product",{"name":21,"type":19},"Zoom",{"name":23,"type":24},"Gatekeeper","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":25,"icon":11,"name":27,"slug":28},"Malware","malware",[30,35,37],{"category":31},{"id":32,"icon":11,"name":33,"slug":34},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":36},{"id":25,"icon":11,"name":27,"slug":28},{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[43],{"type":28,"value":44,"context":45},"CloudSyncD","Name of the macOS backdoor"]