Security News

Fake Zoom Installer Delivers Stealthy New macOS Backdoor

Infosecurity Magazine · 1 Oct 2026
Key Takeaway Only install software like Zoom from official sources and be wary of any installer that asks you to disable built-in Mac security settings.

Researchers at Jamf Threat Labs have identified a new piece of macOS malware called CloudSyncD, which is distributed through a disk image designed to look like a genuine Zoom installer. First spotted on 15 September in a development build, it was found just two days later configured against live command-and-control servers across multiple domains, suggesting the operation is moving towards active deployment.

Once opened, the fake installer instructs victims to manually override macOS Gatekeeper protections through System Settings, then presents a fake authorisation prompt that checks the entered password against the local account. Jamf notes the password is not sent to attackers directly; instead it is hidden within a decoy file using invisible characters and used locally to launch a second, hidden payload with elevated privileges. This payload runs on both Apple silicon and Intel Macs and is designed to avoid leaving traces on disk where possible.

Once active, CloudSyncD sets up a hidden folder on the device and communicates with its command-and-control server using encrypted traffic, sending system details and a hardware identifier during check-ins. Despite requesting a password, Jamf found no built-in functions for stealing browser data, Keychain credentials or cryptocurrency wallets, suggesting the malware's main purpose is gaining and maintaining elevated access rather than direct credential theft.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.