#CloudSyncD
Fake Zoom installer hides macOS backdoor CloudSyncD
Fake Zoom installer hides macOS backdoor CloudSyncD
Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters.
securityaffairs.com
October 3, 2026 at 4:29 PM
New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords

CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers.
#hackernews #news
New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers.
hackread.com
October 2, 2026 at 4:48 PM
Fake Zoom macOS installers are delivering CloudSyncD, a persistent backdoor that tricks users into entering passwords, profiles the host, and connects to C2 infrastructure. #CloudSyncD #Zoom #Jamf
MacOS Users Targeted By Fake Zoom Installer Carrying CloudSyncD Backdoor
Researchers found CloudSyncD hidden inside a fake Zoom macOS installer, where it uses social engineering to trick victims into entering their password and launching the malware. The campaign has moved from testing to deployment, delivering a persistent backdoor that profiles the host, communicates with C2 infrastructure, and avoids traditional infostealer behavior....
www.hendryadrian.com
October 2, 2026 at 4:15 PM
Fake Zoom installer hides macOS backdoor CloudSyncD
Fake Zoom installer hides macOS backdoor CloudSyncD
Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters.
securityaffairs.com
October 4, 2026 at 10:31 PM
CloudSyncD MacOS Backdoor Used Fake Zoom Installer to Steal Passwords #Cloud #CyberSecurity #macOS
CloudSyncD MacOS Backdoor Used Fake Zoom Installer to Steal Passwords
Cybersecurity researchers have identified a new macOS backdoor called CloudSyncD that uses a fake Zoom installer to trick users into providing their computer passwords. The malware was discovered by Jamf Threat Labs and uses a two-stage infection process to gain elevated access and communicate with attacker-controlled servers. One of the most unusual features of the malware is its use of zero-width Unicode characters to hide information about a stolen password inside what appears to be a normal configuration file. Technical Details CloudSyncD is distributed through a malicious disk image designed to look like a legitimate Zoom installer. The installer includes instructions telling users to bypass macOS Gatekeeper by going to System Settings and manually allowing the application to run. Once the fake installer is launched, the first-stage program, called app_installer, displays a fake authorization window asking for the user’s administrator password. It checks the entered password locally using macOS’s dscl command. If the password is incorrect, the malware can continue prompting the victim. The stolen password is not immediately sent to the attackers. Instead, the malware stores it inside a file called data.json. The password is Base64-encoded and placed inside a larger string containing random characters. The malware then uses U+200B ZERO WIDTH SPACE and U+200C ZERO WIDTH NON-JOINER characters. These characters are invisible during normal viewing and encode the location and length of the hidden password. This technique allows malicious information to be concealed without obviously changing the appearance of the file.  The second stage is an embedded Mach-O executable capable of running on both Intel-based and Apple Silicon Macs. The malware attempts to execute the payload without initially writing it to disk. When that approach fails because of macOS security protections, it can create a temporary file and use the captured password with sudo to execute the backdoor with elevated privileges. Impact After execution, CloudSyncD collects information about the infected Mac, including hardware and operating-system details, account information and network-related data. It communicates with a command-and-control server and can periodically check for additional instructions. Researchers observed check-ins occurring approximately every 8 to 16 seconds in analyzed samples. The backdoor can receive executable files or compressed archives, potentially allowing attackers to deploy additional malware on an infected system. 
dlvr.it
October 3, 2026 at 1:10 PM
Fake Zoom installer hides macOS backdoor CloudSyncD

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried i…
#hackernews #news
Fake Zoom installer hides macOS backdoor CloudSyncD
Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]
securityaffairs.com
October 4, 2026 at 10:02 PM
📢 CloudSyncD : backdoor macOS en deux étapes dissimulé dans un faux installateur Zoom

Le 30 septembre 2026, Jamf Threat Labs publie une analyse technique détaillée de CloudSyncD, un backdoor macOS en deux étapes découvert lors d'une…

🟢 vérification factuelle haute
#CloudSyncD #Zoom #Cyberveille
CloudSyncD : backdoor macOS en deux étapes dissimulé dans un faux installateur Zoom
Le 30 septembre 2026, Jamf Threat Labs publie une analyse technique détaillée de CloudSyncD, un backdoor macOS en deux étapes découvert lors d'une surveillance de routine sur VirusTotal. Le malware a été identifié pour la première fois le 15 septembre 2026 dans une version encore en développement, puis des builds configurés contre une infrastructure live ont été observés deux jours plus tard.
cyberveille.ch
October 5, 2026 at 9:00 PM
A new macOS backdoor named CloudSyncD has been identified, gaining access via a fake Zoom installer. Researchers from Jamf Threat Labs found that the malware captures user passwords and hides them in a seemingly normal configuration file.
Fake Zoom installer delivers new CloudSyncD macOS backdoor
www.scworld.com
October 1, 2026 at 4:18 PM
CloudSyncD: macOS backdoor hidden in a fake Zoom installer
CloudSyncD: macOS backdoor hidden in a fake Zoom installer
www.jamf.com
October 3, 2026 at 5:54 PM
Fake Zoom Installer Deploys CloudSyncD MacOS Backdoor and Hides Password in Zero-Width Unicode https://packetstorm.news/news/view/44556 #news
October 1, 2026 at 8:08 PM
Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor
Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor
A fake Zoom installer is tricking Mac users into handing over their login passwords and launching CloudSyncD, a newly identified backdoor. The malware hides inside an application that looks familiar, using installation instructions and counterfeit prompts to turn routine setup into a privileged infection. The first sample appeared on September 15, 2026, while still under development. Within two days, researchers found related builds pointing to reachable command servers across two domains, suggesting a move toward deployment. The report does not establish infection numbers, affected organizations, or confirmed downstream losses. Jamf Threat Labs researchers identified the malware during routine monitoring of executables uploaded to VirusTotal. Jamf said in a report shared with Cyber Security News (CSN) that CloudSyncD uses two stages, with the backdoor already embedded inside the installer rather than fetched separately. The immediate risk is unauthorized execution with elevated privileges and a channel for additional malicious programs. Although the password lure resembles an information stealer, researchers found no built-in collection of browser records, keychain items, or cryptocurrency wallets, distinguishing it from recent MacSync malware campaigns that combine theft with remote access. Fake Zoom Installer Tricks Mac Users The disk image presents a familiar installation layout, pairing an application icon with an Applications shortcut. Its background adds step-by-step instructions directing users into System Settings, then Privacy & Security, where they are told to select Open Anyway and enter their administrator password. The app_installer dropper (Source – Jamf) These directions bypass Gatekeeper because the application lacks a trusted developer signature. The approach depends on persuasion rather than an operating-system exploit, echoing fake conferencing software updates that encourage people to override safeguards while believing they are completing a legitimate installation. After launch, a counterfeit authorization dialog requests the user’s password. The installer checks the response against the local account and repeats the prompt until authentication succeeds. A fake download progress window helps maintain the appearance of a normal setup process. The captured password is concealed inside an apparently ordinary settings file. Its base64-encoded value sits between random filler characters, while 48 invisible Unicode characters appended to the version field identify its position and length. The report describes local storage, but no password transmission to attackers. The installer first tries to launch its embedded payload without leaving a conventional executable on disk. That attempt failed during testing because of macOS protections. It then writes a temporary copy and uses the captured password to run the backdoor with elevated privileges. Backdoor Awaits Additional Payloads CloudSyncD supports both Apple silicon and Intel Macs. On first contact, it sends a device survey containing hardware details, operating-system information, account and machine names, and network information. Later check-ins carry only the hardware identifier, with live-build traffic observed every eight to 16 seconds. The server can return encrypted tasks containing executable programs, either directly or inside compressed archives. This differs from a conventional remote shell: researchers expect newly launched binaries rather than arbitrary shell commands, making process monitoring important when investigating suspected activity. A fake authorization prompt (Source – Jamf) Its endpoints imitate requests for a JavaScript library, helping traffic resemble ordinary web activity. Both stages accept any presented server certificate. Shared encryption material across the analyzed builds also gives defenders a way to correlate samples and decode captured communications. The encrypted log records can reveal the contacted server, device identifier, and check-in history. Researchers also noted that password validation exposes the supplied credential in process arguments, creating a useful detection opportunity. Researchers did not observe persistence, a completed application replacement, or delivery of remote tasks. Unlike fake CAPTCHA backdoor infections that establish startup mechanisms, the tested samples remained at their staging locations. Those limits matter: available evidence supports a working privileged backdoor, not every intended feature. Jamf recommends blocking and reporting similar threats through endpoint and web protections. For investigation, its report highlights encrypted implant logs, invisible characters in settings files, temporary payload patterns, and password-validation command lines. The complete source indicators below preserve those hunting details without adding unpublished hashes. Indicators of compromise (IoCs):- Type Indicator Description SHA-256 faf2eea05f3c9f1c4ef8f6be339f5459a38f95cfd9d512bc24e2803230e5c7bf Distribution disk image. SHA-256 524a7bcc8edcadc6f4381459f79769e1ec534aa78f66e5c38a6678bd55cf2572 Development-build dropper, arm64. SHA-256 071d58f590d155b8ef991a9fe6f9c0a85ccc190d5266c770b5296e4550e084a5 Embedded development-build implant, universal binary. SHA-256 74fea25aba11fef0572ecef3dda0c819e6841150f3154bee2e26ec71c06c85ed Embedded development implant, arm64 slice, 379,600 bytes. SHA-256 8371abbfeb3dbab1581eee54688ecd1f0640dc013ddb419c4332fcd954f9d2bc Embedded development implant, x86_64 slice, 351,392 bytes. SHA-256 f7d8a7593ccbbcb05fde2bf110e1c5d09b18f711219e6b80edda83ae8b41a1e1 On-disk implant copy, arm64 slice, 379,600 bytes. Shared content hash b3acff0abcdde6adc91cb97461b4d902ff19375752afa2f778f682f5102bdfc4 Hash of 371,408 arm64 bytes preceding the code signature; matches both development copies. SHA-256 74dfa21b837c0c4e6abd428a1370ccd8779428d2c9362981a06ce26c6a58b353 Live x86_64 dropper using the orchid-led endpoint. SHA-256 5f2aebc518a56ebe0cc9171553e2c5973ddbfa79042c1c76b665d8b465c1695d Corresponding live arm64 dropper using the orchid-led endpoint. SHA-256 cc54d90920a73cc5e176664f61c6f601c95d693e431e79ae1148cb91e83c9235 Live arm64 dropper using the bjzhishang endpoint. SHA-256 989c2235b3deec9a0d7cb3eb10d8148735cb704dc85de4e16211381fa794dca1 Corresponding live x86_64 dropper using the bjzhishang endpoint. SHA-256 63c88ba846d1adf047417502e67a20f6e52414fea4b4b80aa66c5a371f53dcd6 Orchid-led implant, universal binary, 678,336 bytes. SHA-256 54efb0e308c93e448187ca53abe62eca6521bc84852a63b2ffefdd00e9771882 Orchid-led implant, x86_64 slice, 325,904 bytes. SHA-256 96e039a67b2ab39e36d57a988b3af16b2822d9dfaa70892be06178826b1eb261 Orchid-led implant, arm64 slice, 334,272 bytes. SHA-256 edcd4a8ca2d525f26b8cd05a533585842b1e38216d98e385e25abf8703d31010 Bjzhishang implant, universal binary, 756,432 bytes. SHA-256 c279201898cb0c645343a0e3b4215ad324b0edacc4df799f22e78a8cfbe10d06 Bjzhishang implant, arm64 slice, 379,600 bytes. SHA-256 06ab1e44941e0ceea9df11729576a091fa8c0388188b599f0ee51c54ee0a3186 Bjzhishang implant, x86_64 slice, 351,392 bytes. C2 URL hxxps://orchid-led[.]com/macos/jquery[.]js Live command-and-control endpoint. C2 URL hxxps://bjzhishang[.]com/macos/jquery[.]js Second live command-and-control endpoint. Domain orchid-led[.]com Live command-and-control domain. Domain bjzhishang[.]com Second live command-and-control domain. C2 URL hxxp://192[.]168[.]2[.]133:9099/ops Development-build endpoint; private network address that did not answer during testing. IP address 192[.]168[.]2[.]133 Private development endpoint, not a public attack-infrastructure address. URL path /macos/jquery[.]js Shared live endpoint path disguised as a JavaScript resource. Filename Zoom.dmg Malicious distribution disk image. Application bundle Zoom.app Bundle impersonating the legitimate conferencing client. Volume name Zoom Mounted disk-image volume name. Filename app_installer Stage-one dropper executable. Filepath /Volumes/Zoom/Zoom.app/Contents/MacOS/app_installer Dropper location in the mounted image. Relative filepath Zoom.app/Contents/MacOS/app_installer Dropper bundle path reported in the analysis. Filename appd Configured stage-two payload filename. Filename cshelper On-disk payload filename and signing identifier. Filepath /Volumes/Zoom/Zoom.app/Contents/Resources/cshelper On-disk copy of the embedded implant. Signing identifier main-arm64.out Identifier retained in embedded arm64 payload signatures. Process name cloudsyncd Configured daemon name and process disguise; not observed as a runtime rename. Directory ~/.local/share/cloudsync/ Configured implant installation directory. Log filepath ~/.local/share/cloudsync/.config/logs/sync.err Encrypted implant log containing session and beacon information. Filename sync.err Implant log filename. Configuration filepath ~/.config/<name>/data.json Decoy configuration pattern; source reports mode 0644. Filename data.json Settings file concealing the captured login password. Directory ~/.config/zoom/ Development-build configuration directory. Directory ~/.config/cloudsync/ Live-build configuration directory. Unicode marker U+200B Zero Width Space used in the hidden credential index. Unicode marker U+200C Zero Width Non-Joiner used in the hidden credential index. Temporary filepath $TMPDIR/.app_swap_<pid>.sh Self-deleting application-bundle replacement script. Filename pattern .app_swap_<pid>.sh Runtime-generated bundle-swap script name. Filename prefix .app_swap_ Recommended hunting prefix for the transient replacement script. Temporary filepath $TMPDIR/.s_XXXXXX Stage-two temporary-file fallback passed to privileged execution. Filename prefix .s_ Recommended hunting prefix for temporary stage-two payloads. Temporary directory $TMPDIR/.opXXXXXX/ Directory used to unpack tasked payload archives; removed after use. Temporary filepath <install dir>/.t_XXXXXX Tasked-payload fallback; unlinked after launch. Filename p.tgz Task archive extracted inside the temporary task directory. Directory pattern bin/ Extracted executable tree inside a tasked package. Payload path pattern bin/<daemon> Executable location within a server-delivered archive. Package filename .r.tar.gz Intended replacement-application package; its download URL was empty in analyzed builds. Extended attribute com.apple.provenance Attribute stripped from a tasked-payload fallback before execution. C2 channel key 61957119137f9492ab7cff41ed83619c Encryption material reused across development and live builds. C2 initialization vector d398b8d4 Initialization vector reused across analyzed builds. String obfuscation key D7 19 BF 57 E6 5B A0 9D E1 BA CD B1 82 C9 91 18 ED AF D5 18 FD 3A 4A 97 97 BC AD 22 1A DB 81 51 Shared 32-byte obfuscation table in both malware stages. Command line /usr/bin/dscl /Local/Default -authonly <user> <password> Local password validation; exposes the credential in process arguments. Command line /usr/bin/sudo -S --preserve-env=HOME,USER $TMPDIR/.s_XXXXXX Privileged implant launch using the captured password on standard input. Command line sh -c mkdir -p '<install dir>/.config/logs' 2>/dev/null Creates the implant’s logging directory. Command line sh -c /usr/sbin/ioreg -rd1 -c IOPlatformExpertDevice 2>/dev/null Collects the host hardware identifier. Process command /usr/bin/tar xzf -C Archive extraction command used for server-delivered tasks. Interpreter /bin/bash Interpreter used for the transient bundle-swap script; not malicious by itself. Execution path /dev/fd Attempted fileless execution route that failed during testing. Sample collection URL VirusTotal collection Source-provided sample collection, not malicious infrastructure. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor appeared first on Cyber Security News .
cybersecuritynews.com
October 1, 2026 at 3:24 PM
CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS #CloudSyncDMalware #FakeZoomInstaller #MacSecurity
CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS
Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS. Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It is initiated by the use of a disk image that is made to resemble the Zoom installer. When a package is opened, it appears as a volume titled Zoom and uses familiar installation elements to create the impression that the application is genuine.  As part of the installation process, the fake installer displays a password prompt as part of the fake installer, which bypasses macOS Gatekeeper, permitting the ad-hoc signed application to run despite the operating system's security checks. CloudSyncD checks the credentials entered against the local account before the malware continues. Instead of transmitting the password immediately, CloudSyncD stores it locally within a fake configuration file in lieu of transmitting it to a third party.  Through a normal inspection of the file, it may be difficult to identify the password because it is concealed using encoded data and invisible zero-width Unicode characters. The stolen password is then used as a means of executing the malware's second stage with elevated privileges. Within the dropper, CloudSyncD is packaged as a universal Mach-O binary capable of being executed on Intel as well as Apple silicon Macs.  The malware attempts to execute the payload using an anonymous file descriptor as a first step, avoiding conventional file writing methods. It is possible to write the payload to disk temporarily and execute it by using sudo using the captured password, if that method fails as a result of macOS security protections.  Instead of stealing information conventionally, the second stage functions as a backdoor. It establishes communication with the attacker's infrastructure and receives additional executable files or compressed archived archives. CloudSyncD's second-stage implant is relatively quiet after it has been injected. It provides a way for the operator to deliver further malware or tools after the initial compromise.  By creating a working directory and maintaining encrypted activity logs, the malware avoids the need for a visible persistence mechanism. Check-ins occur every 8 to 16 seconds and include a hardware identifier, suggesting a periodic check-in is occurring. Compared to a simple command shell, the C2 channel provides the attackers with greater flexibility.  Using CloudSyncD, the compromised Mac can be supplied with compressed archives or executables, which can then be used to run the supplied content. Jamf Threat Labs identified multiple later builds of the backdoor communicating with two live domains following the initial infection. This enables the backdoor to serve as a delivery mechanism for additional malware or tools. They use the same URI structure, which was designed to resemble a request for a jQuery script.  Both domains were registered with the same registrar in 2011 and were protected by Cloudflare. As of the time of the researchers’ analysis, neither domain was flagged by a security service. A number of technical similarities were also observed between the different samples, including similar string-obfuscation schemes, installation paths, daemon names, and process disguise schemes.  More importantly, the builds shared the same C2 encryption key and initialization vector, which means network traffic captured from different versions could potentially be decrypted using recovered configuration material. According to the findings, CloudSyncD had moved from an unfinished test build to a functional backdoor utilizing social engineering, while maintaining a relatively simple infection route.  Researchers distinguish the malware from a conventional infostealer despite the fact that it collects system and user information for reconnaissance. Rather than being sent to the attackers, the captured password is used locally to obtain elevated privileges, while the backdoor's primary function is to provide access and facilitate the execution of additional payloads.
dlvr.it
October 5, 2026 at 7:11 PM
Un falso instalador de Zoom ataca a usuarios de macOS con la puerta trasera CloudSyncD

Investigadores de Jamf detectaron el malware en pleno desarrollo a mediados de septiembre, y días después ya encontraron muestras activas en dos dominios distintos, señal de que pasó de pruebas a despliegue…
Un falso instalador de Zoom ataca a usuarios de macOS con la puerta trasera CloudSyncD
Investigadores de Jamf detectaron el malware en pleno desarrollo a mediados de septiembre, y días después ya encontraron muestras activas en dos dominios distintos, señal de que pasó de pruebas a despliegue real. (Fuente: SecurityWeek) Investigadores de Jamf encontraron un dropper para macOS escondido dentro de un cliente de Zoom disfrazado. El malware se identifica como CloudSyncD, y está diseñado para instalar una puerta trasera persistente y sigilosa.
infosertecla.com
October 6, 2026 at 9:00 PM
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor www.securityweek.com/macos-users-...
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
www.securityweek.com
October 4, 2026 at 3:42 PM
A fake Zoom installer for Mac can leave users with CloudSyncD instead of Zoom—and hidden, long-term access for attackers.

Jamf researchers found newer versions on two sites…

https://en.hacks.gr/pseytiko-zoom-gia-mac-mporei-na-dosei-stoys-drastes-kryfi-makrochronia-prosvasi/

#Zoom #Mac #CloudSyncD
October 4, 2026 at 11:08 AM
Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15 […]
Original post on poliverso.org
poliverso.org
October 3, 2026 at 4:07 PM
New macOS malware masquerades as Zoom installer

www.macworld.com/article/3247...
New macOS malware masquerades as Zoom installer
Dubbed CloudSyncD, the malware attacks both M-series and Intel Macs.
www.macworld.com
October 4, 2026 at 1:15 PM
CloudSyncD: Neue Mac-Malware tarnt sich als Zoom-Installer

Neue Mac-Malware CloudSyncD tarnt sich als Zoom-Installer und richtet eine Backdoor auf macOS ein – wie der Angriff funktioniert und warum…

https://appletechnikblog.com/2026/10/02/cloudsyncd-neue-mac-malware-tarnt-sich-als-zoom-installer/
CloudSyncD: Neue Mac-Malware tarnt sich als Zoom-Installer
Neue Mac-Malware CloudSyncD tarnt sich als Zoom-Installer und richtet eine Backdoor auf macOS ein – wie der Angriff funktioniert und warum Gatekeeper allein nicht schützt. Mehr erfahrt Ihr hier
appletechnikblog.com
October 2, 2026 at 12:25 PM
macOSユーザーを標的とした偽Zoomインストーラーが、CloudSyncDバックドアを仕掛けている。
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
A macOS dropper was found inside a disguised Zoom client. The malware is tracked as CloudSyncD and is designed to deliver a stealthy backdoor.
www.securityweek.com
October 2, 2026 at 5:55 PM