Fake Zoom installer drops CloudSyncD backdoor on macOS with root privileges
Jamf Threat Labs says a new macOS backdoor, CloudSyncD, poses as a Zoom installer, tricks users into entering their password and uses it with sudo to run a persistent implant as root.
At a glance
- Jamf Threat Labs found a development build of CloudSyncD on September 15, 2026, and live samples within two days
- A fake Zoom disk image asks for the Mac password, checks it locally and uses sudo to launch the backdoor as root
- The implant profiles the host, disguises its C2 beacon as a jQuery script fetch and runs Mach-O payloads or tar archives sent by operators
- Both stages are only ad-hoc signed, so victims must manually bypass Gatekeeper; no attribution has been made
A newly discovered macOS backdoor called CloudSyncD is being spread through a fake Zoom installer that persuades victims to type in their Mac password and then uses it to run the implant with root privileges, Jamf Threat Labs said in research published on September 30. According to Jamf, it spotted an unfinished development build on September 15, and within two days configured samples were communicating with live command-and-control servers, suggesting the operation had moved from testing to deployment. SecurityWeek, which reported on the findings on October 2, noted that the malware is a persistent backdoor rather than an infostealer.
What happened
Jamf said the malware arrives as a disk image that mounts as a volume named "Zoom" and imitates a normal Mac installer. Because the bundle carries only an ad-hoc signature, Gatekeeper refuses to open it; the disk image background instructs the victim to override that block through System Settings > Privacy & Security. The development build showed clear signs of being unfinished, including a C2 address on a private network, a placeholder log encryption key and verbose debug logging, the researchers said. Later builds were configured against two separate domains registered in 2011 through the same registrar and placed behind Cloudflare.
Technical details
The first-stage binary, app_installer, displays a fake authorization dialog asking the user to "enter your password to allow this", validates the password against the local account with dscl, and then shows a fake "Downloading Zoom..." progress window, according to Jamf. The password is Base64-encoded and hidden in ~/.config/zoom/data.json, with its position encoded in invisible zero-width Unicode characters. Jamf stressed that the password is not sent to the attackers; it is used locally with sudo to launch the embedded second-stage Mach-O, first attempting fileless execution and falling back to a temporary file on disk.
The second stage runs under the daemon name cloudsyncd, which gives the family its name. Jamf said the implant decrypts its configuration at runtime, sends an initial survey of about 2 KB containing hardware ID, CPU, RAM, OS version, machine name, user name, MAC address and model, and then checks in with only the hardware UUID every 8 to 16 seconds. Its beacon URI is disguised to look like a jQuery script request. Operators can deliver gzipped tar archives or raw Mach-O executables, which the backdoor runs directly instead of executing shell commands. Both stages are universal binaries for Apple silicon and Intel Macs, with no evidence of notarization. Jamf noted that in its testing the implant did not establish a LaunchAgent or LaunchDaemon.
Who is affected
The campaign targets macOS users who download Zoom from unofficial sources. Jamf did not attribute the malware to a known group, but said identical obfuscation tables, paths and encryption keys across all builds point to a single operator.
What to do
Users should install Zoom only from the vendor's official site and never follow instructions to bypass Gatekeeper. Jamf recommended monitoring for ad-hoc signed executables requesting sudo, unusual dscl password checks, new LaunchAgent or LaunchDaemon items, and the directories ~/.config/zoom/ and ~/.local/share/cloudsync/. Jamf Protect customers can set threat prevention and web protection to block and report similar threats.
Sources
- CloudSyncD: macOS backdoor hidden in a fake Zoom installer — Jamf Threat Labs
- macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor — SecurityWeek
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



