A macOS backdoor is riding inside a Zoom client that only looks genuine. Jamf researchers caught the implant, tracked as CloudSyncD, while it was still in development in mid-September. Days later, fresh samples showed it had crossed from testing into live use.
The trick is familiar social engineering. What arrives is a disk image the victim opens, and it mounts under the name Zoom. Inside sits a dropper that has to be started by hand, as the victim is walked through a fake Zoom setup.
Jamf says the development build hides a full universal Mach-O inside the dropper, a payload of roughly 756 KB. It is unpacked at runtime. Jamf adds that a second copy waits inside the app bundle on disk, so the dropper can pull its payload from either spot.
The dropper hands the extracted code to an anonymous file descriptor, then tries to run it. Apple’s System Integrity Protection stops that in most cases, so it falls back to writing the file to disk and running it with sudo, using the password the victim handed over while activating.
A successful run leaves a daemon called CloudSyncD. The implant keeps its settings encrypted inside the executable and unlocks them only while running. Its beacons imitate a jQuery script fetch and reach two domains registered in 2011 through one registrar, both behind Cloudflare; neither had any detections at press time.
Every build draws on one string-obfuscation table, the same install paths and daemon name, and even the same command-and-control key and initialization vector, so traffic from any sample can be decrypted. CloudSyncD is not an infostealer: the stolen password is used only on the host to gain root. Its job is quiet, long-term access for staging later payloads, plus host profiling and exfiltration to its controller.
