Fake Zoom installer deploys CloudSyncD backdoor on macOS

Jamf researchers found macOS malware disguised as a Zoom installer that mounts a disk image and, after users enter their password, installs a persistent CloudSyncD backdoor.

Jamf researchers discovered a macOS dropper that impersonates a Zoom installer and installs a persistent backdoor called CloudSyncD. The first development build appeared in mid-September, and additional samples surfaced within days.

The infection begins with social engineering: victims are directed to download what appears to be a Zoom installer. The download mounts as a disk image labeled Zoom and presents an activation flow that asks the user for their password. The dropper contains a universal Mach-O payload embedded inside itself and also stored in the application bundle.

The dropper attempts to execute the payload from an anonymous file descriptor. When System Integrity Protection prevents that execution, the dropper writes the payload to disk and executes it with sudo using the password supplied during activation. Successful execution results in installation of the CloudSyncD daemon with root privileges.

Early development builds used a private-network command-and-control address and left verbose debug logging enabled. Researchers later found multiple builds hosted on two separate domains. Both domains use the same URI path that mimics a jQuery script fetch so the beacon traffic resembles ordinary JavaScript requests. The domains were registered in 2011 through the same registrar and were behind Cloudflare; they showed no detections at the time of analysis.

Analysis found consistent tooling across builds. Jamf researchers wrote: “Every build shares the same string obfuscation table, the same install paths, daemon name and process disguise, and, more tellingly, the same C2 key and initialization vector, down to the identical per-string seeds.” Because of this uniformity, captured beacon traffic can be decrypted using material recovered from any single build, and on-host indicators remain consistent across samples.

CloudSyncD stores its configuration encrypted inside the binary and decrypts it at runtime. Once active, the backdoor profiles the host, performs reconnaissance and sends system and user details to its command-and-control servers. The malware is designed to provide long-term access so operators can deliver additional payloads.

Although the delivery flow resembles an infostealer, CloudSyncD does not include standard information-stealing modules. The password phished during activation is used locally to gain root privileges for executing the backdoor and is not transmitted to the attackers.

Jamf published a list of indicators of compromise tied to the observed builds and recommended monitoring for the file paths, daemon name and beacon activity that recur across samples. Researchers also noted the samples use native macOS code, string obfuscation and execution paths that attempt to avoid writing payloads to disk while relying on social engineering to obtain credentials.

Articles by this author