New macOS Malware CloudSyncD Spreading as Zoom Installer
Security firm Jamf Threat Labs has identified a new macOS malware named CloudSyncD that disguises itself as a Zoom installer. It tricks users into disabling security features and revealing administrator credentials.
A new strain of macOS malware, dubbed CloudSyncD, has been observed bypassing security measures by impersonating the installer for Zoom conferencing software. According to security company Jamf Threat Labs, the malware lures users into disabling macOS's built-in Gatekeeper security feature and entering their administrator password. This action allows attackers to establish a hidden backdoor on affected Mac computers.
The malware is often distributed through fraudulent websites designed to mimic legitimate Zoom installers. The malicious installation files contain instructions prompting users to disable Gatekeeper and provide their administrator credentials. Completing these steps grants the malware system access, enabling the creation of a backdoor.
Once a user provides the password, the malware stores it within a configuration file, using invisible Unicode characters to mark its location. The backdoor program can then execute commands with administrator privileges and receive remote instructions from attackers. These instructions can include downloading executable files or compressed archives, facilitating further malicious activity.
Jamf Threat Labs advises Mac users to download applications exclusively from the App Store and exercise caution when prompted for administrator passwords. Most legitimate macOS applications do not require a password during installation. Users should verify the source of any software before proceeding with installation to mitigate security risks.