Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor
A fake Zoom installer tricks Mac users into launching CloudSyncD, a new privileged backdoor.
Jamf Threat Labs identified CloudSyncD, a new macOS backdoor hidden inside a fake Zoom installer disk image. The first sample appeared on VirusTotal on September 15, 2026, and related builds pointed to reachable command servers within two days. The unsigned dropper instructs users to bypass Gatekeeper, captures the local password in a disguised settings file, and launches an embedded universal implant with elevated privileges. Researchers observed device surveys and check-ins every 8 to 16 seconds, but not persistence or completed remote-task delivery, and no victim count was reported.