Close Menu
NCIJ Network NCIJ Network
    What's Hot

    G7 agrees major release of oil stocks following pressure from the US – POLITICO

    October 2, 2026

    Greens can move Labour in the right direction, says Zack Polanski

    October 2, 2026

    Amazon Says It’s No Longer Using NDAs for Data Centers

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • G7 agrees major release of oil stocks following pressure from the US – POLITICO
    • Greens can move Labour in the right direction, says Zack Polanski
    • Amazon Says It’s No Longer Using NDAs for Data Centers
    • Vulnerability Backlogs Are an Ownership Problem
    • ‘Uptober’ Off With a Bang as Bitcoin Surges to $86K
    • Are hypernovas real?
    • BP taking the wheel of Namibian license trio as farm-in deal clear final regulatory gate
    • Oregon Housing Director Failed to Report Husband’s Related Business Interests — ProPublica
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 2, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A macOS dropper has been found inside a disguised Zoom client. The malware is tracked as CloudSyncD and is designed to deliver a persistent and stealthy backdoor.

    Researchers at Jamf first noticed this malware still in development in mid-September. Within days, other samples were found suggesting it has now progressed from testing and development to deployment. 

    The malware infection process is initiated by any of the standard social engineering methods designed to persuade or trick victims into downloading dangerous content. In this case it is malware hidden in malicious code disguised as a Zoom Mac installer. If the phish is successful, a malware dropper is delivered to the victim as a disk image that mounts as a volume named Zoom. This dropper contains the payload but must be activated by the victim – hence the disguise as a Zoom installer. The victim is guided through the activation thinking it will install Zoom, but it actually installs CloudSyncD. 

    The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The same payload is also present on disk inside the application bundle, so the dropper has two sources for it,” say the researchers.

    The payload is written to an anonymous file descriptor, and the dropper attempts to execute it. Execution will fail in most cases because of the MacOS System Integrity Protection. If so, the dropper writes the file temporarily to disk and executes it using sudo along with the user’s password collected during the activation process. 

    The result of successful activation is implementation of the CloudSyncD malware. Its configuration is stored encrypted in the binary and decrypted at runtime. It runs through a daemon named CloudSyncD. The malware first analyzed by the researchers had not reached deployment stage. The C2 address was on a private network, and verbose debug logging was left on.

    Advertisement. Scroll to continue reading.

    Now, however, the researchers have seen several malware builds on two separate domains. The URI path is identical in both, masquerading as a jQuery script so a beacon resembles an ordinary JavaScript fetch. Both domains were registered in 2011 through the same registrar and sit behind Cloudflare, and neither carried any detections at the time of writing.

    “Every build shares the same string obfuscation table, the same install paths, daemon name and process disguise, and, more tellingly, the same C2 key and initialization vector, down to the identical per-string seeds,” say the researchers. “Only the endpoint changes. Captured beacon traffic is therefore decryptable with material recovered from any build, and the on-host indicators hold across all of them.”

    This discovery and analysis of new malware from development to deployment demonstrates how macOS malware continues to move toward native implementations, string protection, and execution paths that attempt to avoid writing payloads to disk – while still depending on the oldest attacker technique available: socially engineering victims to hand over their password.

    CloudSyncD serves as a persistent backdoor designed to establish stealthy, long-term access to the infected Mac allowing attackers to deploy follow-up payloads. It conducts host profiling and reconnaissance and exfiltrates system and user details to its C2. It appears in initial delivery process to be similar to an infostealer, but this is not an infostealer in function. It contains no standard infostealer information-stealing functionality. The phished user password, for example, is not exfiltrated but solely used locally to grant root privileges for executing the ongoing backdoor.

    Since the malware has now reached deployment, the researchers also provide a long list of IOCs to monitor.

    Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

    Related: Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates

    Related: Recent macOS Screen Sharing Vulnerability Exploited in Attacks

    Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    Backdoor carrying CloudSyncD Fake Installer macOS targeted users Zoom
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Vulnerability Backlogs Are an Ownership Problem

    OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

    Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    Rolling the cyber dice with open-source and open-weight AI models

    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    G7 agrees major release of oil stocks following pressure from the US – POLITICO

    October 2, 2026

    Greens can move Labour in the right direction, says Zack Polanski

    October 2, 2026

    Amazon Says It’s No Longer Using NDAs for Data Centers

    October 2, 2026

    Vulnerability Backlogs Are an Ownership Problem

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    G7 agrees major release of oil stocks following pressure from the US – POLITICO

    October 2, 2026

    Greens can move Labour in the right direction, says Zack Polanski

    October 2, 2026

    Amazon Says It’s No Longer Using NDAs for Data Centers

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.