Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake Zoom Installer Deploys macOS Backdoor “CloudSyncD” to Harvest Credentials

A counterfeit Zoom DMG disguises a password‑stealing dropper that hides credentials using zero‑width Unicode characters. The technique underscores the need for robust security‑awareness training and privileged‑access monitoring in audit‑ready control programs.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Fake Zoom Installer Deploys macOS Backdoor “CloudSyncD”

What Happened — Researchers at Jamf Threat Labs discovered a malicious macOS installer masquerading as the Zoom client. The dropper prompts users for their macOS password, encodes it with zero‑width Unicode characters, and stores it in a fake settings file before loading a hidden Mach‑O payload.

Why It Matters for Trust & Control Assurance

  • Demonstrates how credential‑theft attacks bypass native gatekeeping (Gatekeeper, SIP) and exploit user trust in familiar brands.
  • Highlights the need for continuous security‑awareness training and verification of software provenance as core controls in a control‑assurance program.
  • Provides a concrete example of why organizations must collect and retain evidence of user‑training completion and privileged‑access monitoring to satisfy audit requirements.

Who Is Affected — Enterprises and individuals that install Zoom on macOS devices, spanning technology, SaaS, and remote‑work environments.

Recommended Actions

  • Enforce strict software‑origin verification (e.g., signed packages, notarization) and block ad‑hoc‑signed installers.
  • Deploy security‑awareness training that covers social‑engineering tactics such as fake installers and zero‑width character obfuscation.
  • Implement continuous monitoring of privileged‑account activity and retain logs of password entry attempts for audit readiness.

Technical Notes

  • Delivery: Phished DMG file that appears as a “Zoom” volume, instructing users to bypass Gatekeeper.
  • Credential capture: Password validated locally via dscl, then base64‑encoded and hidden in a data.json file using 48 invisible Unicode characters.
  • Payload execution: Attempts fileless in‑memory execution; falls back to writing the Mach‑O payload to disk when System Integrity Protection blocks the former.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/200293/malware/fake-zoom-installer-hides-macos-backdoor-cloudsyncd.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →