CloudSyncD macOS Backdoor Hides Passwords in Fake Zoom Installer
Jamf says the CloudSyncD macOS backdoor, posed as a Zoom installer, captures a password with invisible Unicode and contacts live command servers.
Jamf Threat Labs reported CloudSyncD, a macOS backdoor shipped in a disk image that imitates a Zoom installer and coaches users to override Gatekeeper and supply an administrator password. The dropper checks that password locally—GBHackers specifies dscl—and hides it with zero-width Unicode; only GBHackers states that a base64 copy is written to ~/.config/zoom/data.json with those characters marking offset and length. The password then starts an embedded universal Mach-O payload named cloudsyncd with elevated privileges on Apple silicon and Intel, though accounts differ: GBHackers describes a failed fileless attempt followed by sudo, while Infosecurity Magazine says execution is attempted through /dev/fd. The implant sends a host survey and beacons over HTTPS every 8 to 16 seconds; GBHackers identifies orchid-led.com and bjzhishang.com URLs impersonating jquery.js and says tasks can be encrypted Mach-O or gzipped tar files, whereas Cyber Security News reported no completed remote-task delivery in testing. Sources agree a September 15, 2026 build was followed within two days by samples using live command-and-control, but they disagree on whether that first file was a discovery, a development build, or the earliest VirusTotal upload, and on whether the dropper is ad-hoc-signed or unsigned. Jamf did not confirm infections or a victim count and said analysis found no persistence and no browser, Keychain, or wallet-theft features.
- Jamf Threat Labs described CloudSyncD, a macOS backdoor in a fake Zoom disk image that tells users to bypass Gatekeeper and enter an administrator password.
- The password is validated locally—GBHackers specifies dscl—and hidden with zero-width Unicode; only GBHackers says a base64 copy is stored in ~/.config/zoom/data.json, with those characters marking offset and length.
- That password launches an embedded universal Mach-O stage named cloudsyncd with elevated privileges on Apple silicon and Intel; GBHackers describes a failed fileless attempt then sudo, while Infosecurity Magazine says execution is…
- The implant surveys the host and beacons over HTTPS every 8 to 16 seconds; GBHackers names orchid-led.com and bjzhishang.com paths impersonating jquery.js.
- GBHackers says it can receive encrypted Mach-O or gzipped tar tasks; Cyber Security News said testing did not show completed remote-task delivery.
- A September 15, 2026 sample was followed within two days by builds using live command-and-control; sources call it a discovery, a development build, or the first VirusTotal upload.
- Sources disagree on signing: GBHackers says the dropper is ad-hoc-signed, while Cyber Security News calls it unsigned.
- Jamf reported no confirmed infections or victim count, no persistence in analysis, and no browser, Keychain, or wallet-theft functions.
Coverage timelineoldest first · each row is one article
- · 10h agoCloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords in Plain Sight
GBHackers· 62
CloudSyncD, a fake Zoom macOS backdoor, hides phished passwords with invisible Unicode and calls live C2.
- · 8h agoCloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
Infosecurity Magazine· 56
Jamf found CloudSyncD, a macOS backdoor in a fake Zoom installer that captures a password to launch its payload.
- · 6h agoFake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor
Cyber Security News· 63