Malware

Fake Zoom installer delivers new CloudSyncD macOS backdoor

A new macOS backdoor dubbed CloudSyncD has been discovered, which gains initial access through a fake Zoom installer, Jamf Threat Labs researchers reported Wednesday.

The malware was first discovered through a VirusTotal sample and initially appeared still in development, but more recent samples were found to connect to live infrastructure, suggesting an active campaign was underway, according to Jamf.

The fake installer, a disk image that mounts as a volume under the name “Zoom,” displays instructions designed to convince the victim to override Gatekeeper protection by manually clicking “Open Anyway” in security settings. It also displays a prompt for the user to enter their password and validates the password using dscl.

While the user sees a fake progress window that makes it appear as though the Zoom application is downloading, their password gets written to a file under ~/.config/zoom/ with the name “data.json.” This file looks like a normal Zoom configuration file but hides the password in a “cache” value in a base64-encoded format with randomly generated filler characters placed before and after it.

So the attackers can retrieve the password later in the attack while still hiding it from analysis, the malware encodes the password’s length and offset using two different invisible zero-width Unicode characters: the U+200C zero width non-joiner and U+200B zero width space. Based on the number of each character hidden within the file’s “version” field, the attacker can know where to find the base64-encoded password buried among the filler characters.

The Mach-O payload executable gets embedded within the dropper and extracted at runtime, with the malware first attempting to execute it via /dev/fd without writing it to the disk. However, this method failed in Jamf’s tests, with the researchers noting it would likely fail on most macOS systems because of System Integrity Protection. As a fallback, the dropper writes the file temporarily to the disk via mkstemp and executes it with sudo, leveraging the user’s password.

CloudSyncD backdoor executes fileless Mach-O payloads

The final payload runs as a universal Mach-O implant that retrieves its command-and-control (C2) address from an encrypted configuration file and beacons every 8 to 16 seconds. Upon execution, it creates a working tree, begins writing logs to ~/.local/share/cloudsync/.config/logs/sync.err and sends a survey of host information to the remote server.

The backdoor receives tasks from the C2 server as JSON objects and executes any raw Mach-O it receives. It also accepts gzipped tar archives, which it unpacks with /usr/bin/tar.

“Tasking delivers executables, not shell commands, so the observable is a newly written or fileless Mach-O rather than suspicious shell activity,” the Jamf researchers wrote.

Jamf also noted that the malware does not act as an infostealer and doesn’t target browser data, keychain items or cryptocurrency wallets; it only steals the user’s password to further its attack chain and does not appear to exfiltrate it. It also does not use persistence mechanisms such as LaunchAgent or LaunchDaemon plists.

“CloudSyncD is a good reminder that although infostealers may dominate the threat landscape, attackers still have use for quieter malware that lies low until further access is needed,” the researchers concluded.

The use of fake Zoom installers to spread malware is a common tactic used in job recruitment or business meeting themed attacks, where victims are asked to install Zoom to join a video call with a recruiter, colleague or business partner. The technique has previously been used by North Korean and Iranian state-sponsored threat actors. Jamf has not attributed CloudSyncD to any specific threat actor.

Laura French

Laura French has been a staff reporter for SC Media since 2023. Laura writes daily news stories, contributes to feature stories, covers industry events and edits briefs for the SC Media website. A New Jersey native, Laura graduated from Ramapo College in 2016 and has previously written for Labcompare, FireRescue1, EMS1 and Forensic Magazine.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds