Fake Zoom Installer Deploys macOS Backdoor “CloudSyncD”
What Happened — Researchers at Jamf Threat Labs discovered a malicious macOS installer masquerading as the Zoom client. The dropper prompts users for their macOS password, encodes it with zero‑width Unicode characters, and stores it in a fake settings file before loading a hidden Mach‑O payload.
Why It Matters for Trust & Control Assurance
- Demonstrates how credential‑theft attacks bypass native gatekeeping (Gatekeeper, SIP) and exploit user trust in familiar brands.
- Highlights the need for continuous security‑awareness training and verification of software provenance as core controls in a control‑assurance program.
- Provides a concrete example of why organizations must collect and retain evidence of user‑training completion and privileged‑access monitoring to satisfy audit requirements.
Who Is Affected — Enterprises and individuals that install Zoom on macOS devices, spanning technology, SaaS, and remote‑work environments.
Recommended Actions
- Enforce strict software‑origin verification (e.g., signed packages, notarization) and block ad‑hoc‑signed installers.
- Deploy security‑awareness training that covers social‑engineering tactics such as fake installers and zero‑width character obfuscation.
- Implement continuous monitoring of privileged‑account activity and retain logs of password entry attempts for audit readiness.
Technical Notes
- Delivery: Phished DMG file that appears as a “Zoom” volume, instructing users to bypass Gatekeeper.
- Credential capture: Password validated locally via
dscl, then base64‑encoded and hidden in adata.jsonfile using 48 invisible Unicode characters. - Payload execution: Attempts fileless in‑memory execution; falls back to writing the Mach‑O payload to disk when System Integrity Protection blocks the former.
Source: Security Affairs