Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A fake Zoom installer is tricking Mac users into handing over their login passwords and launching CloudSyncD, a newly identified backdoor.

The malware hides inside an application that looks familiar, using installation instructions and counterfeit prompts to turn routine setup into a privileged infection.

The first sample appeared on September 15, 2026, while still under development. Within two days, researchers found related builds pointing to reachable command servers across two domains, suggesting a move toward deployment.

The report does not establish infection numbers, affected organizations, or confirmed downstream losses. Jamf Threat Labs researchers identified the malware during routine monitoring of executables uploaded to VirusTotal.

Jamf said in a report shared with Cyber Security News (CSN) that CloudSyncD uses two stages, with the backdoor already embedded inside the installer rather than fetched separately.

The immediate risk is unauthorized execution with elevated privileges and a channel for additional malicious programs.

Although the password lure resembles an information stealer, researchers found no built-in collection of browser records, keychain items, or cryptocurrency wallets, distinguishing it from recent MacSync malware campaigns that combine theft with remote access.

Fake Zoom Installer Tricks Mac Users

The disk image presents a familiar installation layout, pairing an application icon with an Applications shortcut. Its background adds step-by-step instructions directing users into System Settings, then Privacy & Security, where they are told to select Open Anyway and enter their administrator password.

The app_installer dropper (Source - Jamf)
The app_installer dropper (Source – Jamf)

These directions bypass Gatekeeper because the application lacks a trusted developer signature. The approach depends on persuasion rather than an operating-system exploit, echoing fake conferencing software updates that encourage people to override safeguards while believing they are completing a legitimate installation.

After launch, a counterfeit authorization dialog requests the user’s password. The installer checks the response against the local account and repeats the prompt until authentication succeeds. A fake download progress window helps maintain the appearance of a normal setup process.

The captured password is concealed inside an apparently ordinary settings file. Its base64-encoded value sits between random filler characters, while 48 invisible Unicode characters appended to the version field identify its position and length.

The report describes local storage, but no password transmission to attackers. The installer first tries to launch its embedded payload without leaving a conventional executable on disk.

That attempt failed during testing because of macOS protections. It then writes a temporary copy and uses the captured password to run the backdoor with elevated privileges.

Backdoor Awaits Additional Payloads

CloudSyncD supports both Apple silicon and Intel Macs. On first contact, it sends a device survey containing hardware details, operating-system information, account and machine names, and network information.

Later check-ins carry only the hardware identifier, with live-build traffic observed every eight to 16 seconds. The server can return encrypted tasks containing executable programs, either directly or inside compressed archives.

This differs from a conventional remote shell: researchers expect newly launched binaries rather than arbitrary shell commands, making process monitoring important when investigating suspected activity.

A fake authorization prompt (Source - Jamf)
A fake authorization prompt (Source – Jamf)

Its endpoints imitate requests for a JavaScript library, helping traffic resemble ordinary web activity. Both stages accept any presented server certificate. Shared encryption material across the analyzed builds also gives defenders a way to correlate samples and decode captured communications.

The encrypted log records can reveal the contacted server, device identifier, and check-in history. Researchers also noted that password validation exposes the supplied credential in process arguments, creating a useful detection opportunity.

Researchers did not observe persistence, a completed application replacement, or delivery of remote tasks. Unlike fake CAPTCHA backdoor infections that establish startup mechanisms, the tested samples remained at their staging locations.

Those limits matter: available evidence supports a working privileged backdoor, not every intended feature. Jamf recommends blocking and reporting similar threats through endpoint and web protections.

For investigation, its report highlights encrypted implant logs, invisible characters in settings files, temporary payload patterns, and password-validation command lines. The complete source indicators below preserve those hunting details without adding unpublished hashes.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 faf2eea05f3c9f1c4ef8f6be339f5459a38f95cfd9d512bc24e2803230e5c7bf Distribution disk image.
SHA-256 524a7bcc8edcadc6f4381459f79769e1ec534aa78f66e5c38a6678bd55cf2572 Development-build dropper, arm64.
SHA-256 071d58f590d155b8ef991a9fe6f9c0a85ccc190d5266c770b5296e4550e084a5 Embedded development-build implant, universal binary.
SHA-256 74fea25aba11fef0572ecef3dda0c819e6841150f3154bee2e26ec71c06c85ed Embedded development implant, arm64 slice, 379,600 bytes.
SHA-256 8371abbfeb3dbab1581eee54688ecd1f0640dc013ddb419c4332fcd954f9d2bc Embedded development implant, x86_64 slice, 351,392 bytes.
SHA-256 f7d8a7593ccbbcb05fde2bf110e1c5d09b18f711219e6b80edda83ae8b41a1e1 On-disk implant copy, arm64 slice, 379,600 bytes.
Shared content hash b3acff0abcdde6adc91cb97461b4d902ff19375752afa2f778f682f5102bdfc4 Hash of 371,408 arm64 bytes preceding the code signature; matches both development copies.
SHA-256 74dfa21b837c0c4e6abd428a1370ccd8779428d2c9362981a06ce26c6a58b353 Live x86_64 dropper using the orchid-led endpoint.
SHA-256 5f2aebc518a56ebe0cc9171553e2c5973ddbfa79042c1c76b665d8b465c1695d Corresponding live arm64 dropper using the orchid-led endpoint.
SHA-256 cc54d90920a73cc5e176664f61c6f601c95d693e431e79ae1148cb91e83c9235 Live arm64 dropper using the bjzhishang endpoint.
SHA-256 989c2235b3deec9a0d7cb3eb10d8148735cb704dc85de4e16211381fa794dca1 Corresponding live x86_64 dropper using the bjzhishang endpoint.
SHA-256 63c88ba846d1adf047417502e67a20f6e52414fea4b4b80aa66c5a371f53dcd6 Orchid-led implant, universal binary, 678,336 bytes.
SHA-256 54efb0e308c93e448187ca53abe62eca6521bc84852a63b2ffefdd00e9771882 Orchid-led implant, x86_64 slice, 325,904 bytes.
SHA-256 96e039a67b2ab39e36d57a988b3af16b2822d9dfaa70892be06178826b1eb261 Orchid-led implant, arm64 slice, 334,272 bytes.
SHA-256 edcd4a8ca2d525f26b8cd05a533585842b1e38216d98e385e25abf8703d31010 Bjzhishang implant, universal binary, 756,432 bytes.
SHA-256 c279201898cb0c645343a0e3b4215ad324b0edacc4df799f22e78a8cfbe10d06 Bjzhishang implant, arm64 slice, 379,600 bytes.
SHA-256 06ab1e44941e0ceea9df11729576a091fa8c0388188b599f0ee51c54ee0a3186 Bjzhishang implant, x86_64 slice, 351,392 bytes.
C2 URL hxxps://orchid-led[.]com/macos/jquery[.]js Live command-and-control endpoint.
C2 URL hxxps://bjzhishang[.]com/macos/jquery[.]js Second live command-and-control endpoint.
Domain orchid-led[.]com Live command-and-control domain.
Domain bjzhishang[.]com Second live command-and-control domain.
C2 URL hxxp://192[.]168[.]2[.]133:9099/ops Development-build endpoint; private network address that did not answer during testing.
IP address 192[.]168[.]2[.]133 Private development endpoint, not a public attack-infrastructure address.
URL path /macos/jquery[.]js Shared live endpoint path disguised as a JavaScript resource.
Filename Zoom.dmg Malicious distribution disk image.
Application bundle Zoom.app Bundle impersonating the legitimate conferencing client.
Volume name Zoom Mounted disk-image volume name.
Filename app_installer Stage-one dropper executable.
Filepath /Volumes/Zoom/Zoom.app/Contents/MacOS/app_installer Dropper location in the mounted image.
Relative filepath Zoom.app/Contents/MacOS/app_installer Dropper bundle path reported in the analysis.
Filename appd Configured stage-two payload filename.
Filename cshelper On-disk payload filename and signing identifier.
Filepath /Volumes/Zoom/Zoom.app/Contents/Resources/cshelper On-disk copy of the embedded implant.
Signing identifier main-arm64.out Identifier retained in embedded arm64 payload signatures.
Process name cloudsyncd Configured daemon name and process disguise; not observed as a runtime rename.
Directory ~/.local/share/cloudsync/ Configured implant installation directory.
Log filepath ~/.local/share/cloudsync/.config/logs/sync.err Encrypted implant log containing session and beacon information.
Filename sync.err Implant log filename.
Configuration filepath ~/.config/<name>/data.json Decoy configuration pattern; source reports mode 0644.
Filename data.json Settings file concealing the captured login password.
Directory ~/.config/zoom/ Development-build configuration directory.
Directory ~/.config/cloudsync/ Live-build configuration directory.
Unicode marker U+200B Zero Width Space used in the hidden credential index.
Unicode marker U+200C Zero Width Non-Joiner used in the hidden credential index.
Temporary filepath $TMPDIR/.app_swap_<pid>.sh Self-deleting application-bundle replacement script.
Filename pattern .app_swap_<pid>.sh Runtime-generated bundle-swap script name.
Filename prefix .app_swap_ Recommended hunting prefix for the transient replacement script.
Temporary filepath $TMPDIR/.s_XXXXXX Stage-two temporary-file fallback passed to privileged execution.
Filename prefix .s_ Recommended hunting prefix for temporary stage-two payloads.
Temporary directory $TMPDIR/.opXXXXXX/ Directory used to unpack tasked payload archives; removed after use.
Temporary filepath <install dir>/.t_XXXXXX Tasked-payload fallback; unlinked after launch.
Filename p.tgz Task archive extracted inside the temporary task directory.
Directory pattern bin/ Extracted executable tree inside a tasked package.
Payload path pattern bin/<daemon> Executable location within a server-delivered archive.
Package filename .r.tar.gz Intended replacement-application package; its download URL was empty in analyzed builds.
Extended attribute com.apple.provenance Attribute stripped from a tasked-payload fallback before execution.
C2 channel key 61957119137f9492ab7cff41ed83619c Encryption material reused across development and live builds.
C2 initialization vector d398b8d4 Initialization vector reused across analyzed builds.
String obfuscation key D7 19 BF 57 E6 5B A0 9D E1 BA CD B1 82 C9 91 18 ED AF D5 18 FD 3A 4A 97 97 BC AD 22 1A DB 81 51 Shared 32-byte obfuscation table in both malware stages.
Command line /usr/bin/dscl /Local/Default -authonly <user> <password> Local password validation; exposes the credential in process arguments.
Command line /usr/bin/sudo -S --preserve-env=HOME,USER $TMPDIR/.s_XXXXXX Privileged implant launch using the captured password on standard input.
Command line sh -c mkdir -p '<install dir>/.config/logs' 2>/dev/null Creates the implant’s logging directory.
Command line sh -c /usr/sbin/ioreg -rd1 -c IOPlatformExpertDevice 2>/dev/null Collects the host hardware identifier.
Process command /usr/bin/tar xzf -C Archive extraction command used for server-delivered tasks.
Interpreter /bin/bash Interpreter used for the transient bundle-swap script; not malicious by itself.
Execution path /dev/fd Attempted fileless execution route that failed during testing.
Sample collection URL VirusTotal collection Source-provided sample collection, not malicious infrastructure.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor appeared first on Cyber Security News.