Skip to content

CloudSyncD: fake Zoom installer backdoors macOS, steals passwords

Jamf Threat Labs found CloudSyncD, a new macOS backdoor delivered by a fake Zoom installer that social-engineers past Gatekeeper and hides the user's password in a fake config file.

Published 3 min read

Jamf Threat Labs has identified CloudSyncD, a new macOS backdoor distributed through a fake Zoom installer that talks users into bypassing Gatekeeper themselves, then harvests the account password and beacons to a command-and-control server. Primary writeup: Jamf Threat Labs, with coverage at SecurityWeek and SC World.

What it does

The fake installer displays its own instructions coaching the victim to right-click and choose "Open Anyway" in System Settings — a social-engineered Gatekeeper bypass rather than a code-signing exploit. It then prompts for the account password behind a fake "downloading Zoom" progress window.

The entered password is written to:

~/.config/zoom/data.json

The file masquerades as a normal Zoom configuration. The password is stashed in a cache value, base64-encoded with randomly generated filler characters before and after it to frustrate casual inspection. Reporting notes the use of zero-width Unicode to further obscure the stored secret.

Once running, CloudSyncD collects a host survey — hardware UUID, processor, memory, and device details — sends it to C2, and then checks in every 8 to 16 seconds for further instructions, including executable files or compressed archives to run.

Exploitation status

Active. Jamf first found a development build on September 15, 2026, and located samples configured to reach live C2 infrastructure two days later. The earliest sample surfaced via VirusTotal and looked unfinished; the later ones connect to reachable servers, indicating a campaign in progress rather than a lab artifact.

Action checklist

  1. Block and alert on the artifact path ~/.config/zoom/data.json — the real Zoom client does not store credentials there.
  2. Hunt for processes beaconing on a tight 8–16s interval to unrecognized hosts from endpoints that recently "installed Zoom" outside your managed software catalog.
  3. Reinforce the user-facing message that "Open Anyway" is the attack — no legitimate installer needs you to override Gatekeeper by hand.
  4. If a host is suspect, treat the local account password as compromised: rotate it and any credentials typed on that machine.
  5. Pull Jamf's published IOCs and load them into your EDR; do not rely on signature detection alone for a backdoor this new.

Context

The pattern is consistent: macOS infostealers and backdoors increasingly skip memory-corruption exploits entirely and just ask the user to disarm their own defenses, because a convincing installer UI is cheaper than a Gatekeeper bypass and works often enough. The twist here — stashing the password inside a plausible data.json with Unicode and base64 padding — is about surviving a quick look by a responder, not about privilege. Detection on the artifact beats detection on the binary.

Related stories