LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
phishing

Fake Zoom installer hides macOS backdoor CloudSyncD

Jamf Threat Labs has uncovered a new macOS backdoor, dubbed CloudSyncD, which is distributed through a fake Zoom installer. The malware was first observed in development on September 15, 2026, and quickly transitioned to live command-and-control infrastructure within two days.

ZeroDay News ·

Source: Security Affairs

Jamf Threat Labs has uncovered a new macOS backdoor, dubbed CloudSyncD, which is distributed through a fake Zoom installer. The malware was first observed in development on September 15, 2026, and quickly transitioned to live command-and-control infrastructure within two days.

The distribution method employs a common macOS social engineering tactic. Victims receive a disk image named "Zoom" that contains an application icon and an "Applications" shortcut. A background image within the disk image provides instructions on how to bypass macOS Gatekeeper, as the application is only ad-hoc signed and would otherwise be blocked.

Upon launching the fake Zoom application, users are presented with a persistent dialog requesting their password, ostensibly to continue the installation. This prompt continues until a correct password for the local account is entered, which the dropper validates using `dscl`.

Once a valid password is provided, a deceptive "Downloading Zoom..." progress window appears. The stolen password is not immediately transmitted. Instead, it is base64 encoded, padded with random filler text, and embedded within a field resembling an innocent cache value in a fake settings file named `data.json`. This file is formatted to mimic ordinary application preferences, including theme and language settings, making it appear innocuous.

The method for retrieving the hidden password gives the file its name. Following a visible version number, "1.0.0," the file contains 48 invisible Unicode characters, specifically zero-width spaces and non-joiners. These characters, when decoded, reveal the starting position and length of the real password within the padded text. The amount of filler text varies with each execution, ensuring the password's position changes while the retrieval technique remains constant.

The malware's payload, a universal Mach-O file approximately 756 KB in size, is embedded directly within the dropper rather than being downloaded separately. The dropper initially attempts to execute this payload from memory via an anonymous file descriptor, aiming to avoid writing it to disk. However, Jamf's testing confirmed that this method typically fails on most macOS systems due to System Integrity Protection, logging an error: `/dev/fd spawn failed rc=13`.

When the fileless execution fails, the malware resorts to writing the payload to a temporary file using `mkstemp` and then executing it with `sudo`, leveraging the previously stolen user password to gain necessary privileges. A cleanup script, assembled at runtime from obfuscated fragments, is designed to replace the malicious app bundle with a legitimate one before self-deletion. However, in the recovered builds, the replacement bundle was absent, rendering this swap mechanism non-functional.

The second stage, which Jamf refers to as `cloudsyncd` after its disguised daemon name, exhibits relatively restrained behavior. It does not establish persistence, install a LaunchAgent, or rename itself. Instead, it creates a working directory, logs its activities with encrypted records, and checks in with its command-and-control server every 8 to 16 seconds, transmitting only a hardware identifier.

The server interaction is a key aspect of CloudSyncD's capabilities. The server can respond by sending either a compressed archive for unpacking or a complete executable to run. This functionality allows the backdoor to deliver and execute entire programs, providing a distinct indicator for defenders to monitor: the creation or execution of suspicious new files, rather than merely a series of unusual terminal commands.

At the time of Jamf's research publication, the malware was communicating with two active domains, both registered through the same registrar in 2011 and protected by Cloudflare. Neither domain was flagged as malicious at that point. All analyzed samples utilized the same encryption key and initialization vector, suggesting that a single recovered sample could potentially be used to decrypt network traffic from other versions of the malware.

CloudSyncD highlights a continued trend in macOS malware towards native implementations, string protection, and sophisticated execution evasion techniques, serving as a reminder that quieter, persistent backdoors remain a significant threat alongside more prevalent infostealers.

phishingcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.