Image: thaicert.or.th · rights & removal
CloudSyncD Malware Disguised as Zoom Installer on macOS Tricks Users into Providing Passwords and Deploys a Backdoor
Reporting by Thailand ThaiCERT AdvisoriesRead the original at thaicert.or.th
Executive Summary
Facts Only
* Researchers from Jamf Threat Labs disclosed the discovery of CloudSyncD malware on macOS on Monday, October 5, 2026.
* The malware disguises itself as a Zoom installer.
* It uses installation page instructions to trick users into bypassing Gatekeeper protections.
* It displays a fake prompt requesting the password for the local account.
* When a password is entered, the malware validates it against the local account.
* The password is encoded in Base64 and stored in a data.json file with additional data and invisible Unicode characters.
* The password is used to launch a second-stage backdoor with sudo privileges.
* The payload is embedded within the installer.
* The backdoor collects basic system information and connects to C2 infrastructure to receive files or archives.
* Researchers did not observe the user’s password being transmitted to the C2 server during testing.
* Researchers found no direct capabilities for stealing data from browsers, Keychain, or cryptocurrency wallets.
* CloudSyncD did not create persistence mechanisms such as LaunchAgent or LaunchDaemon during analysis.
Full Take
From the original · Thailand ThaiCERT Advisories
546/69 Monday, October 5, 2026 Researchers from Jamf Threat Labs have disclosed the discovery of CloudSyncD malware on macOS, which disguises itself as a Zoom installer and uses instructions on the installation page to trick users into bypassing Gatekeeper protections before displaying a fake prompt requesting the password for the local account.Read the full story at thaicert.or.th
Sentinel — Human
The text exhibits characteristics of professional investigative reporting on a technical security discovery, focusing on factual details and actionable warnings.
