CloudSyncD: fake Zoom installer backdoors Macs via your password
Jamf found a fake Zoom installer that asks for your Mac password, then runs the CloudSyncD backdoor with sudo. Here is how to stop it on your team's Macs.
A fake Zoom installer is putting a backdoor on Macs, and it only needs one thing from the user: their password. Jamf Threat Labs found the CloudSyncD backdoor inside a disk image that looks like a Zoom download. The installer shows a fake dialog, checks the password, then uses sudo to run the payload with admin rights. If your team joins client calls from Macs and installs meeting apps from links in emails, this is aimed at you.
What actually happened
From Jamf's analysis, reported by SecurityWeek on October 2:
- Delivery: a DMG that mounts as "Zoom." The background image tells the user how to get past Gatekeeper. Both stages are ad-hoc signed and not notarized, so macOS warns — the user has to override it by hand.
- The password grab: a fake prompt reads "Enter your password to allow this." The malware checks the password locally with
dscl. Jamf says the password is not sent to the attackers. It is used once, withsudo, to run the second stage as root. - What the backdoor does: it profiles the Mac, beacons to a command server, and accepts new payloads (tar archives or Mach-O binaries) to run. That makes it a door for whatever the operators want to send next.
- Hiding in traffic: the two command domains sit behind Cloudflare, and beacon URLs look like jQuery script requests.
- Timeline: Jamf found a development build on September 15, 2026, and saw live deployment on multiple domains within two days.
One correction to early coverage: Jamf says it did not observe persistence — no LaunchAgent or LaunchDaemon was installed in the samples it studied. That can change in a later build.
Why it matters for your business
Zoom does not need a Gatekeeper workaround. The real Zoom installer is signed and notarized. Any "installer" that shows instructions to right-click, open anyway, or change security settings is the attack. Put that rule in front of your staff in one sentence.
Install meeting apps from one place only. Get Zoom from zoom.us/download or your device management tool — never from a link in a calendar invite, a DM or a search ad. We saw the same move with fake ChatGPT ads pushing a RAT.
Daily work should not run as admin. This attack works because the user's password can run sudo. Give staff standard accounts and keep admin rights for a separate login. If you manage Macs with Jamf, Kandji or Intune, push Zoom from there so nobody has a reason to download it.
Check for the obvious leftovers. Jamf notes the first stage writes ~/.config/zoom/data.json. A real Zoom install does not need that file. Search for it on your Macs.
Key takeaways
- CloudSyncD ships as a fake Zoom DMG that asks for the Mac password
- It uses that password with sudo to run a backdoor that accepts new payloads
- The installer is not notarized — any "open anyway" instruction is the red flag
- Install Zoom only from zoom.us or your device management tool
- Run staff on standard accounts, not admin
Running a small team on Macs with no IT person? We set up device management, app deployment and standard-user accounts so a fake installer has nothing to work with. Tell us about your setup.
Sources: Jamf Threat Labs, SecurityWeek.
- #macos
- #malware
- #zoom
- #cloudsyncd
- #endpoint-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Norway proposes AI smart glasses ban: write your recording policy
Norway wants a temporary ban on AI smart glasses in gyms, schools and shopping centers. Here is the recording policy your business needs before your city asks.
Read itFake ChatGPT Custom GPT ads push ClickFix RAT malware
Huntress found Google ads for 'chatgpt' leading to a malicious Custom GPT on chatgpt.com that ends in a ClickFix RAT. Bookmark your AI tools; stop searching.
Read it