Particle.news

macOS Infostealer CloudSyncD Hides Inside Fake Zoom Installer

Researchers say the installer uses on-screen instructions to get users to override Gatekeeper so an unsigned payload can run.

Overview

  • This week Jamf Threat Labs published a technical report, and outlets including Macworld and 9to5Mac confirmed the discovery of CloudSyncD distributed in a disk image that mimics a Zoom installer.
  • The disk image mounts as a volume named Zoom and shows a familiar installer layout while a background image gives step‑by‑step instructions that tell users to open System Settings, choose Privacy & Security, click Open Anyway, and enter an administrator password to bypass Gatekeeper.
  • If run, CloudSyncD runs as a background infostealer that records user‑entered data, checks in with attacker servers as often as every eight seconds, and can accept remote commands for the operator to execute on the infected Mac.
  • Jamf’s analysis shows the campaign is multi‑stage: a fake password prompt is used to elevate and launch a universal payload for both Apple silicon and Intel Macs, the captured password is validated locally rather than sent in clear, and samples have been seen contacting live command‑and‑control domains.
  • Users should only install apps from the Mac App Store or developers’ official websites, avoid running installers from untrusted sources, refuse instructions that tell them to change security settings, and use endpoint detection to watch for unexpected persistence and frequent outbound data transfers as this campaign follows a wider trend of social engineering that undermines Gatekeeper.