Skip to content
Rush Commerce
Field Notes3 min read

CloudSyncD: fake Zoom installer backdoors Macs via your password

Jamf found a fake Zoom installer that asks for your Mac password, then runs the CloudSyncD backdoor with sudo. Here is how to stop it on your team's Macs.

A fake Zoom installer is putting a backdoor on Macs, and it only needs one thing from the user: their password. Jamf Threat Labs found the CloudSyncD backdoor inside a disk image that looks like a Zoom download. The installer shows a fake dialog, checks the password, then uses sudo to run the payload with admin rights. If your team joins client calls from Macs and installs meeting apps from links in emails, this is aimed at you.

What actually happened

From Jamf's analysis, reported by SecurityWeek on October 2:

  • Delivery: a DMG that mounts as "Zoom." The background image tells the user how to get past Gatekeeper. Both stages are ad-hoc signed and not notarized, so macOS warns — the user has to override it by hand.
  • The password grab: a fake prompt reads "Enter your password to allow this." The malware checks the password locally with dscl. Jamf says the password is not sent to the attackers. It is used once, with sudo, to run the second stage as root.
  • What the backdoor does: it profiles the Mac, beacons to a command server, and accepts new payloads (tar archives or Mach-O binaries) to run. That makes it a door for whatever the operators want to send next.
  • Hiding in traffic: the two command domains sit behind Cloudflare, and beacon URLs look like jQuery script requests.
  • Timeline: Jamf found a development build on September 15, 2026, and saw live deployment on multiple domains within two days.

One correction to early coverage: Jamf says it did not observe persistence — no LaunchAgent or LaunchDaemon was installed in the samples it studied. That can change in a later build.

Why it matters for your business

Zoom does not need a Gatekeeper workaround. The real Zoom installer is signed and notarized. Any "installer" that shows instructions to right-click, open anyway, or change security settings is the attack. Put that rule in front of your staff in one sentence.

Install meeting apps from one place only. Get Zoom from zoom.us/download or your device management tool — never from a link in a calendar invite, a DM or a search ad. We saw the same move with fake ChatGPT ads pushing a RAT.

Daily work should not run as admin. This attack works because the user's password can run sudo. Give staff standard accounts and keep admin rights for a separate login. If you manage Macs with Jamf, Kandji or Intune, push Zoom from there so nobody has a reason to download it.

Check for the obvious leftovers. Jamf notes the first stage writes ~/.config/zoom/data.json. A real Zoom install does not need that file. Search for it on your Macs.

Key takeaways

  • CloudSyncD ships as a fake Zoom DMG that asks for the Mac password
  • It uses that password with sudo to run a backdoor that accepts new payloads
  • The installer is not notarized — any "open anyway" instruction is the red flag
  • Install Zoom only from zoom.us or your device management tool
  • Run staff on standard accounts, not admin

Running a small team on Macs with no IT person? We set up device management, app deployment and standard-user accounts so a fake installer has nothing to work with. Tell us about your setup.

Sources: Jamf Threat Labs, SecurityWeek.

  • #macos
  • #malware
  • #zoom
  • #cloudsyncd
  • #endpoint-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.