Jamf Threat Labs has uncovered a new macOS backdoor, dubbed CloudSyncD, which is distributed through a fake Zoom installer. The malware was first observed in development on September 15, 2026, and quickly transitioned to live command-and-control infrastructure within two days.
The distribution method employs a common macOS social engineering tactic. Victims receive a disk image named "Zoom" that contains an application icon and an "Applications" shortcut. A background image within the disk image provides instructions on how to bypass macOS Gatekeeper, as the application is only ad-hoc signed and would otherwise be blocked.
Upon launching the fake Zoom application, users are presented with a persistent dialog requesting their password, ostensibly to continue the installation. This prompt continues until a correct password for the local account is entered, which the dropper validates using `dscl`.
Once a valid password is provided, a deceptive "Downloading Zoom..." progress window appears. The stolen password is not immediately transmitted. Instead, it is base64 encoded, padded with random filler text, and embedded within a field resembling an innocent cache value in a fake settings file named `data.json`. This file is formatted to mimic ordinary application preferences, including theme and language settings, making it appear innocuous.
The method for retrieving the hidden password gives the file its name. Following a visible version number, "1.0.0," the file contains 48 invisible Unicode characters, specifically zero-width spaces and non-joiners. These characters, when decoded, reveal the starting position and length of the real password within the padded text. The amount of filler text varies with each execution, ensuring the password's position changes while the retrieval technique remains constant.
The malware's payload, a universal Mach-O file approximately 756 KB in size, is embedded directly within the dropper rather than being downloaded separately. The dropper initially attempts to execute this payload from memory via an anonymous file descriptor, aiming to avoid writing it to disk. However, Jamf's testing confirmed that this method typically fails on most macOS systems due to System Integrity Protection, logging an error: `/dev/fd spawn failed rc=13`.
When the fileless execution fails, the malware resorts to writing the payload to a temporary file using `mkstemp` and then executing it with `sudo`, leveraging the previously stolen user password to gain necessary privileges. A cleanup script, assembled at runtime from obfuscated fragments, is designed to replace the malicious app bundle with a legitimate one before self-deletion. However, in the recovered builds, the replacement bundle was absent, rendering this swap mechanism non-functional.
The second stage, which Jamf refers to as `cloudsyncd` after its disguised daemon name, exhibits relatively restrained behavior. It does not establish persistence, install a LaunchAgent, or rename itself. Instead, it creates a working directory, logs its activities with encrypted records, and checks in with its command-and-control server every 8 to 16 seconds, transmitting only a hardware identifier.
The server interaction is a key aspect of CloudSyncD's capabilities. The server can respond by sending either a compressed archive for unpacking or a complete executable to run. This functionality allows the backdoor to deliver and execute entire programs, providing a distinct indicator for defenders to monitor: the creation or execution of suspicious new files, rather than merely a series of unusual terminal commands.
At the time of Jamf's research publication, the malware was communicating with two active domains, both registered through the same registrar in 2011 and protected by Cloudflare. Neither domain was flagged as malicious at that point. All analyzed samples utilized the same encryption key and initialization vector, suggesting that a single recovered sample could potentially be used to decrypt network traffic from other versions of the malware.
CloudSyncD highlights a continued trend in macOS malware towards native implementations, string protection, and sophisticated execution evasion techniques, serving as a reminder that quieter, persistent backdoors remain a significant threat alongside more prevalent infostealers.






