Jamf Threat Labs identified CloudSyncD, a universal macOS backdoor distributed in a disk image masquerading as a Zoom installer. The lure persuades users to bypass Gatekeeper and enter their account password into a fraudulent authorization prompt; the installer stores the password in a disguised Zoom configuration file, obscuring it with Base64 encoding, random filler, and zero-width Unicode characters, then uses it locally to launch an elevated second-stage payload.
CloudSyncD supports both Apple silicon and Intel Macs, surveys compromised hosts, communicates with encrypted command-and-control infrastructure every 8–16 seconds, and can execute supplied Mach-O binaries or unpack gzipped tar archives. Researchers found live C2 infrastructure spanning multiple domains after first observing a development-stage build, suggesting progression toward operational deployment, but reported no confirmed infections, persistence mechanism, or attribution. Organizations should block the identified fake-installation delivery pattern, reinforce Gatekeeper and software-installation controls, and investigate suspicious Zoom-related disk images and unexpected password prompts.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Jamf Threat Labs published research detailing CloudSyncD's fake Zoom installer, Gatekeeper-bypass social engineering, local password capture, elevated second-stage execution, and encrypted C2-enabled backdoor capabilities. Jamf reported no confirmed infections, persistence mechanism, or attribution to a specific threat actor.
Two days after its initial discovery, Jamf identified CloudSyncD samples configured with live command-and-control infrastructure across multiple domains, indicating the operation was progressing toward deployment.
Jamf Threat Labs first encountered a development-stage build of the CloudSyncD macOS backdoor through VirusTotal monitoring. The malware was packaged in a disk image masquerading as a Zoom installer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.