Threat reportMalwareTL-2026-2840
CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer (TL-2026-2840), also tracked as CloudSyncD, is a high-severity malware campaign, first published 2026-10-02. It has no confirmed attribution, affects Apple macOS (Apple silicon and Intel), maps to 14 MITRE ATT&CK techniques (T1027, T1033, T1036.005), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-2840
- Threat ID
- TL-2026-2840
- Also known as
- CloudSyncD
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, enterprise, remote-workforce
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
Malware and tooling: CloudSyncD
How CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer works
Jamf Threat Labs disclosed CloudSyncD, a two-stage universal Mach-O macOS backdoor distributed as a fake Zoom installer disk image. The installer phishes the user's login password, uses it with sudo to launch a persistent daemon, and beacons a host survey to Cloudflare-fronted C2 over HTTPS. No threat actor attribution has been stated.
CloudSyncD is a macOS backdoor discovered by Jamf Threat Labs through VirusTotal monitoring. A first development build was seen on 2026-09-15; by 2026-09-17 related builds were configured with reachable C2 on two domains, indicating a move from development to deployment. Jamf published its analysis on 2026-09-30, and trade press followed on 2026-10-01 and 2026-10-02. Infosecurity Magazine notes that no confirmed infections were reported.
Delivery is a disk image (Zoom.dmg) that mounts as a volume named "Zoom" and contains an ad-hoc signed Zoom.app. Custom artwork in the image instructs the user to bypass Gatekeeper by manually approving the app in System Settings. The first-stage dropper (Zoom.app/Contents/MacOS/app_installer) shows a progress window reading "Downloading Zoom..." and an authorization dialog stating "Enter your password to allow this". It validates the supplied password against the local account using dscl.
The password is not exfiltrated. It is Base64-encoded with random padding (32-64 characters) and hidden in a decoy configuration file, ~/.config/zoom/data.json. Its offset and length are encoded as 48 invisible zero-width Unicode characters (U+200B and U+200C) in the "version" field. The dropper carries a complete universal Mach-O (about 756 KB in the development build) and extracts it at runtime. It first tries to execute the payload from an anonymous file descriptor (/dev/fd). When System Integrity Protection blocks that, it falls back to writing a temporary file, run via a .app_swap_<pid>.sh helper, and executing it with sudo using the harvested password.
The second stage installs under ~/.local/share/cloudsync/ (implant at appd, working tree .config/logs/) and runs under the process/daemon name cloudsyncd. Logs go to sync.err, encrypted with ChaCha20-Poly1305. Its C2 configuration is stored encrypted in the binary and decrypted at runtime. Jamf observed no LaunchAgent or LaunchDaemon persistence in the analyzed samples. Persistence is described as a persistent daemon. The implant collects a host survey (hwid, cpu_name, cpu_cores, ram, os, machine_name, user_name, mac, hw_model, ioreg output via /usr/sbin/ioreg -rd1 -c IOPlatformExpertDevice) and beacons every 8-16 seconds. Tasking delivers executables rather than shell commands: gzipped tar archives (extracted with /usr/bin/tar) or raw Mach-O files that are executed directly.
Two C2 domains, orchid-led[.]com and bjzhishang[.]com, were both registered in 2011 through the same registrar and sit behind Cloudflare. Both serve the identical URI path /macos/jquery.js so beacons resemble an ordinary JavaScript fetch. Every build shares the same string-obfuscation table, install paths, daemon name, process disguise, and C2 key/IV across builds. Code-signature build identifiers include main-arm64.out and cshelper. A development build pointed at a private-range endpoint (http://192.168.2.133:9099/ops) that was non-responsive during analysis.
MITRE ATT&CK techniques used in TL-2026-2840
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hidden Files and Directories
Discovery
T1033 System Owner/User Discovery; T1082 System Information Discovery
Credential Access
Execution
T1059.004 Unix Shell; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography
Privilege Escalation
T1548.003 Sudo and Sudo Caching
defense-impairment
Affected products and versions in CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
- Apple — macOS (Apple silicon and Intel)
Vulnerable versions: Hosts where a user runs the fake Zoom installer; universal Mach-O supports arm64 and x86_64
Remediation for CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
Immediate actions
- Hunt macOS endpoints for ~/.local/share/cloudsync/, ~/.config/zoom/data.json and a running process named cloudsyncd
- Block orchid-led.com and bjzhishang.com and alert on HTTPS requests to /macos/jquery.js
- If a host is affected, rotate the local account password and any credentials reused on that host, then reimage
- Quarantine Zoom.dmg / Zoom.app/Contents/MacOS/app_installer matches by SHA256
Workarounds
- Use EDR/MDM to block execution of ad-hoc signed applications launched from mounted disk images
Longer-term hardening
- Keep Gatekeeper enforced and restrict users from approving unsigned or ad-hoc signed apps via MDM
- Distribute Zoom only through managed channels or the official vendor site
- Detect sudo executions of temp-written Mach-O files and writes under ~/.local/share and ~/.config by non-standard apps
- Train users that macOS installers asking for a password after instructions to bypass Gatekeeper are malicious
Timeline of CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
- Jamf Threat Labs encounters the first CloudSyncD development build via VirusTotal monitoring; the build points at a private-range test endpoint.
- Newer samples are found configured for reachable C2 on orchid-led[.]com and bjzhishang[.]com, indicating a shift from development to deployment.
- Jamf's analysis reports no LaunchAgent/LaunchDaemon persistence and no built-in infostealer functionality (no browser data, Keychain or crypto-wallet collection) in the analyzed samples; the implant is a tasking backdoor that runs delivered executables.
- Jamf publishes its technical analysis of CloudSyncD and the fake Zoom installer.
- Infosecurity Magazine, Cyberpress, Cryptika and Hackread report on CloudSyncD; no confirmed infections are reported.
- SecurityWeek reports that macOS users are targeted by the fake Zoom installer carrying the CloudSyncD backdoor.
- BeaconBeagle config search for orchid-led.com and bjzhishang.com returns zero items, so no known beacon-config correlation exists for either C2 domain.
Sources cited for CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
- CloudSyncD: macOS backdoor hidden in a fake Zoom installer (Jamf Threat Labs)
- macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor (SecurityWeek)
- CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer (Infosecurity Magazine)
- Fake Zoom Installer Deploys CloudSyncD macOS Backdoor and Hides Password in Zero-Width Unicode (Cyberpress)
- Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor (Cryptika)
- New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords (Hackread)
Detection coverage for TL-2026-2840
As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2840 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.