CloudSyncD: fake Zoom installer backdoors macOS, steals passwords
Jamf Threat Labs found CloudSyncD, a new macOS backdoor delivered by a fake Zoom installer that social-engineers past Gatekeeper and hides the user's password in a fake config file.
Jamf Threat Labs has identified CloudSyncD, a new macOS backdoor distributed through a fake Zoom installer that talks users into bypassing Gatekeeper themselves, then harvests the account password and beacons to a command-and-control server. Primary writeup: Jamf Threat Labs, with coverage at SecurityWeek and SC World.
What it does
The fake installer displays its own instructions coaching the victim to right-click and choose "Open Anyway" in System Settings — a social-engineered Gatekeeper bypass rather than a code-signing exploit. It then prompts for the account password behind a fake "downloading Zoom" progress window.
The entered password is written to:
~/.config/zoom/data.json
The file masquerades as a normal Zoom configuration. The password is stashed in a cache value, base64-encoded with randomly generated filler characters before and after it to frustrate casual inspection. Reporting notes the use of zero-width Unicode to further obscure the stored secret.
Once running, CloudSyncD collects a host survey — hardware UUID, processor, memory, and device details — sends it to C2, and then checks in every 8 to 16 seconds for further instructions, including executable files or compressed archives to run.
Exploitation status
Active. Jamf first found a development build on September 15, 2026, and located samples configured to reach live C2 infrastructure two days later. The earliest sample surfaced via VirusTotal and looked unfinished; the later ones connect to reachable servers, indicating a campaign in progress rather than a lab artifact.
Action checklist
- Block and alert on the artifact path
~/.config/zoom/data.json— the real Zoom client does not store credentials there. - Hunt for processes beaconing on a tight 8–16s interval to unrecognized hosts from endpoints that recently "installed Zoom" outside your managed software catalog.
- Reinforce the user-facing message that "Open Anyway" is the attack — no legitimate installer needs you to override Gatekeeper by hand.
- If a host is suspect, treat the local account password as compromised: rotate it and any credentials typed on that machine.
- Pull Jamf's published IOCs and load them into your EDR; do not rely on signature detection alone for a backdoor this new.
Context
The pattern is consistent: macOS infostealers and backdoors increasingly skip memory-corruption exploits entirely and just ask the user to disarm their own defenses, because a convincing installer UI is cheaper than a Gatekeeper bypass and works often enough. The twist here — stashing the password inside a plausible data.json with Unicode and base64 padding — is about surviving a quick look by a responder, not about privilege. Detection on the artifact beats detection on the binary.