Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor
A fake Zoom installer tricks Mac users into launching CloudSyncD, a new privileged backdoor.
Jamf Threat Labs identified CloudSyncD, a new macOS backdoor hidden inside a fake Zoom installer disk image. The first sample appeared on VirusTotal on September 15, 2026, and related builds pointed to reachable command servers within two days. The unsigned dropper instructs users to bypass Gatekeeper, captures the local password in a disguised settings file, and launches an embedded universal implant with elevated privileges. Researchers observed device surveys and check-ins every 8 to 16 seconds, but not persistence or completed remote-task delivery, and no victim count was reported.
- CloudSyncD is embedded in a fake Zoom disk image rather than downloaded later.
- Users are coached to override Gatekeeper and enter an administrator password.
- Jamf found the first VirusTotal sample on September 15, 2026.
- The implant supports Apple silicon and Intel and beacons every 8–16 seconds.
- Testing found no persistence or completed delivery of remote tasks.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | bjzhishang.com | uery[.]js Live command-and-control endpoint. C2 URL hxxps://bjzhishang[.]com/macos/jquery[.]js Second live command-and-control endpoin |
| domain | jquery.js | slice, 351,392 bytes. C2 URL hxxps://orchid-led[.]com/macos/jquery[.]js Live command-and-control endpoint. C2 URL hxxps://bjzhish |
| domain | orchid-led.com | ishang implant, x86_64 slice, 351,392 bytes. C2 URL hxxps://orchid-led[.]com/macos/jquery[.]js Live command-and-control endpoint. C2 U |
| domain | zoom.app | m.dmg Malicious distribution disk image. Application bundle Zoom.app Bundle impersonating the legitimate conferencing client. Vo |
| md5 | 61957119137f9492ab7cff41ed83619c | a tasked-payload fallback before execution. C2 channel key 61957119137f9492ab7cff41ed83619c Encryption material reused across development and live buil |
| sha256 | 06ab1e44941e0ceea9df11729576a091fa8c0388188b599f0ee51c54ee0a3186 | d06 Bjzhishang implant, arm64 slice, 379,600 bytes. SHA-256 06ab1e44941e0ceea9df11729576a091fa8c0388188b599f0ee51c54ee0a3186 Bjzhishang implant, x86_64 slice, 351,392 bytes. C2 URL hxx |
Full article1,434 words · extracted from cybersecuritynews.com · click to collapse
A fake Zoom installer is tricking Mac users into handing over their login passwords and launching CloudSyncD, a newly identified backdoor.
The malware hides inside an application that looks familiar, using installation instructions and counterfeit prompts to turn routine setup into a privileged infection.
The first sample appeared on September 15, 2026, while still under development. Within two days, researchers found related builds pointing to reachable command servers across two domains, suggesting a move toward deployment.
The report does not establish infection numbers, affected organizations, or confirmed downstream losses. Jamf Threat Labs researchers identified the malware during routine monitoring of executables uploaded to VirusTotal.
Jamf said in a report shared with Cyber Security News (CSN) that CloudSyncD uses two stages, with the backdoor already embedded inside the installer rather than fetched separately.
The immediate risk is unauthorized execution with elevated privileges and a channel for additional malicious programs.
Although the password lure resembles an information stealer, researchers found no built-in collection of browser records, keychain items, or cryptocurrency wallets, distinguishing it from recent MacSync malware campaigns that combine theft with remote access.
Fake Zoom Installer Tricks Mac Users
The disk image presents a familiar installation layout, pairing an application icon with an Applications shortcut. Its background adds step-by-step instructions directing users into System Settings, then Privacy & Security, where they are told to select Open Anyway and enter their administrator password.
.webp)
These directions bypass Gatekeeper because the application lacks a trusted developer signature. The approach depends on persuasion rather than an operating-system exploit, echoing fake conferencing software updates that encourage people to override safeguards while believing they are completing a legitimate installation.
After launch, a counterfeit authorization dialog requests the user’s password. The installer checks the response against the local account and repeats the prompt until authentication succeeds. A fake download progress window helps maintain the appearance of a normal setup process.
The captured password is concealed inside an apparently ordinary settings file. Its base64-encoded value sits between random filler characters, while 48 invisible Unicode characters appended to the version field identify its position and length.
The report describes local storage, but no password transmission to attackers. The installer first tries to launch its embedded payload without leaving a conventional executable on disk.
That attempt failed during testing because of macOS protections. It then writes a temporary copy and uses the captured password to run the backdoor with elevated privileges.
Backdoor Awaits Additional Payloads
CloudSyncD supports both Apple silicon and Intel Macs. On first contact, it sends a device survey containing hardware details, operating-system information, account and machine names, and network information.
Later check-ins carry only the hardware identifier, with live-build traffic observed every eight to 16 seconds. The server can return encrypted tasks containing executable programs, either directly or inside compressed archives.
This differs from a conventional remote shell: researchers expect newly launched binaries rather than arbitrary shell commands, making process monitoring important when investigating suspected activity.
.webp)
Its endpoints imitate requests for a JavaScript library, helping traffic resemble ordinary web activity. Both stages accept any presented server certificate. Shared encryption material across the analyzed builds also gives defenders a way to correlate samples and decode captured communications.
The encrypted log records can reveal the contacted server, device identifier, and check-in history. Researchers also noted that password validation exposes the supplied credential in process arguments, creating a useful detection opportunity.
Researchers did not observe persistence, a completed application replacement, or delivery of remote tasks. Unlike fake CAPTCHA backdoor infections that establish startup mechanisms, the tested samples remained at their staging locations.
Those limits matter: available evidence supports a working privileged backdoor, not every intended feature. Jamf recommends blocking and reporting similar threats through endpoint and web protections.
For investigation, its report highlights encrypted implant logs, invisible characters in settings files, temporary payload patterns, and password-validation command lines. The complete source indicators below preserve those hunting details without adding unpublished hashes.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.