Particle.news

CloudSyncD Backdoor Masquerades as Zoom Installer to Bypass macOS Gatekeeper

Researchers say the dropper uses a fake Zoom disk image and a phony admin prompt to gain elevated rights and run a hidden backdoor on Intel and Apple silicon Macs.

Overview

  • Jamf Threat Labs found CloudSyncD after spotting a development build on September 15 and observed samples configured to contact live command-and-control servers two days later, signaling the operation moved from testing toward deployment.
  • The malware arrives as a disk image that mounts as a volume named Zoom and uses custom installer artwork to tell users to click Open Anyway in System Settings so Gatekeeper is bypassed.
  • The installer shows a fake authorization window that validates the typed admin password locally, hides the credential inside a decoy config file, and uses it to launch a universal Mach-O second-stage with elevated privileges.
  • The second-stage backdoor tries to run in memory to avoid writing to disk, creates a hidden working directory, collects system details, and checks in with C2 servers every 8 to 16 seconds to receive remote tasks.
  • Jamf has not confirmed any live infections or seen the malware establish persistence during testing, and researchers urge users to install software only from the Mac App Store or official developer sites and to refuse Open Anyway prompts or unexpected admin-password requests.