$ techbeacon▋
Malware

Malicious macOS Tool Masquerading as Zoom Installer Harvests Passwords via CloudSyncD Backdoor

Malicious macOS Tool Masquerading as Zoom Installer Harvests Passwords via CloudSyncD Backdoor

A new macOS backdoor identified as CloudSyncD is distributing itself through a counterfeit Zoom installer, allowing attackers to capture user credentials and bypass Apple's Gatekeeper security layer.

The malicious package appears to be a legitimate Zoom download, but once executed it silently installs the CloudSyncD payload. The backdoor then extracts stored passwords from the victim's system and establishes a persistent connection to remote command‑and‑control (C2) servers, giving threat actors ongoing access to compromised machines.

Security researchers note that the technique exploits a trusted software brand to increase the likelihood of user execution. Zoom remains one of the most widely used video‑conferencing applications on macOS, and many users are accustomed to downloading its installer from various web sources. By mimicking the official installer, the attackers sidestep user suspicion and leverage the trust associated with the Zoom name.

Gatekeeper, Apple's built‑in mechanism for verifying the integrity of downloaded applications, is being circumvented by the fake installer. The malware is signed with a certificate that appears valid to Gatekeeper, allowing it to install without triggering the usual warnings. Once on the system, CloudSyncD harvests passwords stored in browsers and keychain files, then relays the data to external servers controlled by the attackers.

Experts advise macOS users to obtain software exclusively from official channels, such as the Mac App Store or the vendor’s verified website, and to enable stricter Gatekeeper settings that require notarization. Regularly updating the operating system and employing reputable security tools can also help detect and block suspicious activity. As the threat landscape continues to evolve, the incident underscores the importance of vigilance when downloading popular applications, even those that are widely trusted.

Source: Hackread
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related