macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Mac Users Targeted by Sophisticated Malware Disguised as Zoom Installer

A new wave of malware is targeting macOS users, cleverly disguised as a Zoom installer. Dubbed CloudSyncD, this sophisticated backdoor has been found in the wild, delivering persistent and stealthy access to infected Macs. The malware’s development was first noticed by researchers at Jamf in mid-September, but it has since progressed from testing to deployment.

CloudSyncD is delivered through socially engineered methods, tricking victims into downloading a malicious Zoom installer. Once downloaded, a disk image mounts as a volume named “Zoom,” containing the malware dropper. The victim is guided through the activation process, thinking they’re installing Zoom, but in reality, CloudSyncD is installed. This clever disguise allows the malware to evade detection and execution by macOS’s System Integrity Protection.

The payload of CloudSyncD is written to an anonymous file descriptor, but due to System Integrity Protection, it fails to execute most of the time. In such cases, the dropper writes the file temporarily to disk and executes it using sudo along with the user’s password collected during activation. This method allows the malware to bypass security measures and gain root access.

The result is a persistent backdoor that establishes stealthy, long-term access to infected Macs. CloudSyncD conducts host profiling and reconnaissance, exfiltrating system and user details to its command-and-control (C2) server. Unlike traditional infostealers, it doesn’t steal sensitive information like login credentials or financial data; instead, it uses the phished password solely for local execution of the backdoor.

The researchers have observed several builds on two separate domains, both registered in 2011 through the same registrar and protected by Cloudflare. The malware’s C2 address was initially private, but the URI path is identical across all builds, masquerading as a jQuery script to evade detection. The presence of verbose debug logging in early versions suggests that the attackers may have been testing their malware before deployment.

This discovery highlights the evolving nature of macOS malware, which is increasingly adopting native implementations and execution paths designed to avoid writing payloads to disk. Despite these advancements, socially engineered attacks remain a powerful tactic for delivering malware, as seen with CloudSyncD.

As CloudSyncD has now reached deployment, it’s essential for Mac users to be vigilant and monitor their systems closely. By staying informed about the latest threats and best practices, users can protect themselves from sophisticated attacks like this one. To stay safe, keep your operating system and software up-to-date, use strong passwords, and avoid suspicious downloads or email attachments – especially those masquerading as legitimate applications like Zoom.


Source: SecurityWeek — 2026-10-02