A fake Zoom installer dubbed CloudSyncD is coaxing Mac users into switching off Gatekeeper and handing over their admin passwords.
The malware hides itself in the installer window itself, but with unusual instructions. Follow them, and you straight up open a backdoor onto your Mac.
The good news is that you can evade CloudSyncD and any similar malware simply by following one of the most basic security rules when installing applications.
CloudSyncD: Fake Zoom installer looks real
Security firm Jamf Threat Labs discovered the malware and gave it the CloudSyncD name. It was unveiled during routine monitoring of files on VirusTotal.
macOS does a good job of keeping malware at arm’s length, which is why attackers increasingly rely on social engineering to get around its defenses. Gatekeeper, notarization and other built-in security features try to block suspicious software before it runs, so a malicious installer like CloudSyncD has to convince the user to override those protections.
The malware disguises itself as a disk image that mounts as a volume named Zoom, and the layout mimics an ordinary Mac installer. It also has an app icon on the left and an Applications alias on the right.
The only giveaway is the background image. It carries a numbered setup list. Jamf says the steps tell you to open System Settings, head over to Privacy & Security and click Open Anyway. Then you enter the administrator password.
Normally, macOS refuses to open an app Apple hasn’t notarized. Those steps walk you around that protection.
A fake password prompt does the real damage
Once launched, the installer shows a fake authorization window. It then asks for your admin password, checks it against your Mac account and repeats the prompt until you get it right. That’s when the fake download window appears so everything looks normal.
In other words, the fake Zoom installer essentially talks users through disabling one of macOS’s security safeguards and then tricks them into entering an administrator password. The malware isn’t defeating the Mac’s defenses — it’s getting the user to do it for them.
The malware doesn’t send your password to the attackers. Instead, it tucks the password into a decoy settings file that looks like a normal Zoom config, with invisible Unicode characters marking where the password is hidden.
The malware then uses the password to launch a hidden backdoor inside the installer, and runs with elevated privileges.
CloudSyncD is a backdoor you open
The backdoor can run on both Apple Silicon and Intel Macs. According to Jamf, it collects details like your hardware ID, processor, memory, macOS version and username. It then sends them to a command server.
After that, it checks for new orders every 8 to 16 seconds. They can either be an executable to a compressed archive, giving attackers a way to deliver more tools later on.
Jamf found the first sample of CloudSyncD on September 15. That version lacked the usual infostealer tricks. It didn’t gather browsing data, Keychain items or crypto wallets.
But Jamf later discovered newer versions communicating with live command-and-control infrastructure, suggesting the malware has moved beyond testing.
It has not yet been tied to a known threat actor.
How to stay safe from a fake Zoom installer
Fake Zoom installers are a pretty common lure. Attackers often pair them with fake job interviews or business calls, instead someone sends a link and asks you to install Zoom to join.
Make sure you only download apps from the Mac App Store or the official websites of developers you trust. For Zoom, that means zoom.us. Also, never type in your admin password just because an installer window told you to.
If any installer ever tells you to click Open Anyway in System settings, stop. That’s a big red flag.
