Image: securityaffairs.com · rights & removal
Fake Zoom installer hides macOS backdoor CloudSyncD
Reporting by Security Affairs (Pierluigi Paganini)Read the original at securityaffairs.com
Executive Summary
Facts Only
* Jamf Threat Labs found CloudSyncD during routine scanning on VirusTotal.
* The malware was discovered inside a disguised Zoom client.
* Discovery occurred on September 15.
* The threat moved from a private test address to live command-and-control infrastructure on real domains within two days.
* The delivery method involved a disk image appearing as the "Zoom" volume.
* The process guided the victim to bypass Gatekeeper by exploiting an ad-hoc signed application status.
* A user password was requested and validated against the local account during installation.
* The captured password was base64 encoded, padded, and hidden in data.json file.
* The location of the hidden password was determined by analyzing invisible Unicode characters within the version number.
* The malware attempts to execute the payload directly from memory but falls back to writing it to a temporary file and using sudo.
* The second stage implant, cloudsyncd, logs activity and checks in every 8 to 16 seconds with hardware identifiers.
* The C2 server can deliver compressed archives or complete executables.
* The malware communicated with two live domains registered in 2011 and protected by Cloudflare.
* All samples shared the same encryption key and initialization vector.
Full Take
The narrative of CloudSyncD highlights a specific evolution in macOS malware design, moving away from traditional infostealer patterns toward stealthier, native-aware execution paths. The reliance on leveraging user interaction—specifically password entry—remains an ancient mechanism, yet the obfuscation used to steal and hide this credential is highly contemporary, utilizing zero-width characters for hiding data within seemingly benign file structures like configuration files. This demonstrates a persistent tension: attackers employ sophisticated encoding and file system manipulation to obscure low-level actions, while still tethering the final privilege escalation step to a familiar user-facing prompt (the password).
The shift in payload delivery is significant; the attempt at fileless execution via memory execution followed by a fallback to disk writing and sudo execution reflects an ongoing arms race against System Integrity Protection (SIP). The failure mode—relying on $\text{mkstemp}$ and $\text{sudo}$ upon memory execution failure—reveals a strategic concession: acknowledging the blocking mechanism but structuring the payload to exploit fallback mechanisms. This acknowledges that avoiding disk writes is contingent on environmental constraints, forcing reliance on system-level privilege escalation techniques.
The nature of the second stage implant, cloudsyncd, further refines this approach by focusing on command and control flexibility. The ability for the server to deliver full executables rather than discrete shell commands indicates an intent to deploy complex, multi-stage functionality directly into the target environment, providing a richer, more immediate post-compromise objective for the adversary. Furthermore, the reuse of identical encryption keys across samples suggests a centralized infrastructure managing these variants, which provides defenders with a powerful, single point of analysis against a threat actor's operational signature rather than just tracking individual instances.
Bridge Questions: How does the persistence of password-prompting as a core mechanism reflect an inherent limitation in building truly ephemeral malware on modern, security-hardened operating systems? What implications does the shift toward delivering full executables have for future threat hunting methodologies focused on process and file activity versus network telemetry? What architectural assumptions about macOS security can be made when analyzing evasion techniques that explicitly target built-in protections like SIP?
From the original · Security Affairs (Pierluigi Paganini)
Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move from a private test address to live command-and-control infrastructure on real domains.Read the full story at securityaffairs.com
Sentinel — Human
The text reads like a detailed technical breakdown sourced from a security research report, characterized by deep specificity and logical progression typical of human expert analysis rather than generalized synthesis.
