Yaamlabs
Threat intel

CloudSyncD: a fake Zoom installer that backdoors Macs

A fake Zoom disk image talks Mac users past Gatekeeper, phishes their password and runs a root backdoor. How it works, indicators and what to check.

By Yaali. October 3, 2026, 6 min read, Threat intel, Phishing.

Cover illustration of a laptop on a dark desk showing a video call icon, with a glowing cable running to a hidden server box, with the Yaamlabs logo and the text: Fake Zoom installer talks Macs into a root backdoor, 8 to 16 s, between check-ins with the attacker's server

Jamf Threat Labs published research on September 30, 2026 on CloudSyncD, a previously undocumented macOS backdoor that arrives as a fake Zoom installer. The disk image walks the user through switching off Gatekeeper's block for the app, asks for their password in a fake system dialog, then uses that password with sudo to run the backdoor as root. It runs on both Apple silicon and Intel Macs.

The first sample Jamf found, through routine monitoring of files uploaded to VirusTotal, was a development build, seen on September 15. Within two days builds appeared that talked to two live command and control (C2) servers, which suggests the operators were moving from testing to deployment. If your users install meeting software themselves, from links in emails, chats or search results, this one is aimed at them.

CloudSyncD attack chain: the fake Zoom disk image, the Open Anyway step, the fake password prompt, and the root backdoor that checks in every 8 to 16 seconds

How it works

The download is a disk image that mounts as a volume named Zoom, with an app icon on the left and an Applications shortcut on the right, like any normal Mac installer. The app is only ad hoc signed, meaning it carries a signature that proves nothing about who built it, and it is not notarized by Apple, so Gatekeeper blocks it on first launch. The background artwork anticipates this. Its numbered steps tell the user to open System Settings, go to Privacy & Security, scroll to the Security section, click Open Anyway and type their administrator password. The user overrides the protection by hand.

Once running, the first stage, a binary called app_installer inside the app bundle, shows a fake authorization dialog asking for the password again. It checks what was typed against the local account with dscl, the macOS directory service command line tool, and keeps asking until the password is correct. While the user watches a fake progress window that looks like Zoom downloading, the password is written to ~/.config/zoom/data.json, a file built to pass as a Zoom settings file. The password sits base64 encoded inside a long cache value padded with random filler. Its position and length are encoded in 48 invisible characters appended to the version field, using two zero-width Unicode characters, U+200B (zero width space) and U+200C (zero width non-joiner). Opened in a text editor, the file looks normal.

app_installer carries the second stage inside itself: a universal Mach-O binary of about 756 KB. It first tries to run it without touching disk, through /dev/fd, a file descriptor path that lets a process execute data held in memory. System Integrity Protection (SIP) blocks that, so the dropper falls back to writing a temporary file with mkstemp and running it through sudo with the phished password. The backdoor then runs as root under the name cloudsyncd, presented as a background sync service, and writes a log to ~/.local/share/cloudsync/.config/logs/sync.err.

What the backdoor does

On first contact cloudsyncd sends a survey of the machine: hardware UUID, processor, memory, macOS version, account and machine names, and network details. After that it checks in every 8 to 16 seconds. The beacon goes to a path that imitates a jQuery script, so in a proxy log it looks like a web page fetching JavaScript.

Tasks come back in the server's reply. The implant can unpack and run a gzipped tar archive or run a Mach-O executable directly. It does not take shell commands, and it does not steal browser data, Keychain items or cryptocurrency wallets on its own. Its job is to give the operator root on the Mac and run whatever they send next. SecurityWeek and Cloudlink both report that the phished password is used only locally to get root, not sent to the attackers.

Sources differ on persistence. Some coverage describes a persistent backdoor, but in Jamf's own test runs the implant ran from its staging path and created no LaunchAgent or LaunchDaemon. Because it runs any executable with root rights, the operator can add persistence with a later payload, so treat an infected Mac as fully compromised whether or not you find a launch item.

What attackers are doing

Jamf has not attributed CloudSyncD to a known group, and no victim count has been published. The early build pointed at a C2 address on a private network, a sign of testing. The live builds talked to two domains, both registered in 2011 through the same registrar and both behind Cloudflare, with the same URI path:

  • orchid-led[.]com/macos/jquery[.]js
  • bjzhishang[.]com/macos/jquery[.]js

Every build shares the same string obfuscation table, install paths, daemon name, process disguise and C2 encryption key, so the operator can move between servers without changing the implant.

Where to look for CloudSyncD on a Mac and in network logs, and the controls that stop the install

What to do

There is no vulnerability to patch. The infection depends on a person clicking Open Anyway and typing a password, so the fixes are about who can do that and where software comes from.

  1. Take the Gatekeeper override away from users on managed Macs. A configuration profile with the System Policy Managed payload (com.apple.systempolicy.managed) and DisableOverride set to true removes the Open Anyway route for unnotarized apps.
  2. Do not give everyday accounts administrator rights. The sudo step needs an admin password; a standard user's password gets the attacker nothing past the first stage.
  3. Publish Zoom through your device management tool or tell users to install it only from zoom.us or the Mac App Store. Ask users to report any installer whose instructions include clicking Open Anyway.
  4. Block the two C2 domains above at DNS and the web proxy, and alert on requests for /macos/jquery.js to any host.

How to check whether a Mac was hit

On each Mac, look for the files and the process:

  • ls -la ~/.config/zoom/ ~/.local/share/cloudsync/ for data.json and the .config/logs/sync.err log.
  • perl -CSD -ne 'print "hidden characters found\n" if /[\x{200B}\x{200C}]/' ~/.config/zoom/data.json to find the zero-width markers in the version field.
  • ps -axo user,pid,command | grep -i cloudsync for a cloudsyncd process, which will be owned by root.
  • log show --last 14d --predicate 'process == "sudo"' for sudo runs from a temporary path the user cannot explain.

On the network, search DNS, proxy and firewall logs since September 15 for the two domains and for the jQuery path, and look for a Mac making the same HTTPS request every 8 to 16 seconds.

If you find any of this, isolate the Mac and reimage it rather than cleaning it, since root tasking could have changed anything. Change the account password, which is sitting on disk in a recoverable form, and rotate anything that was saved or typed on that Mac since the infection: single sign-on sessions, SSH keys, cloud tokens and VPN credentials.

The wider lesson

Since macOS Sequoia, the Control-click shortcut past Gatekeeper is gone and the only override is Open Anyway in System Settings. CloudSyncD simply prints those steps on its installer artwork. On Macs where the user can click that button and holds an admin password, the attacker needs both and the user supplies both. Removing the override by profile and keeping admin rights for the accounts that need them takes the decision away from whoever happens to see the prompt.

Our safeguarding and hardening team builds the Mac configuration profiles and privilege settings that close the Open Anyway route, and our security operations team can turn the indicators above into alerts. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Jamf Threat Labs, Hackread, SecurityWeek, Cult of Mac, MacTech, Cyberpress, Cybersecurity News, Cloudlink.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.