Threat reportMalwareTL-2026-2840

CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer

highACTIVE

CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer (TL-2026-2840), also tracked as CloudSyncD, is a high-severity malware campaign, first published 2026-10-02. It has no confirmed attribution, affects Apple macOS (Apple silicon and Intel), maps to 14 MITRE ATT&CK techniques (T1027, T1033, T1036.005), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-2840

Threat ID
TL-2026-2840
Also known as
CloudSyncD
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, enterprise, remote-workforce
Target regions
Global
Detection rules
9
Indicators of compromise
22

Malware and tooling in CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer

Malware and tooling: CloudSyncD

How CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer works

Jamf Threat Labs disclosed CloudSyncD, a two-stage universal Mach-O macOS backdoor distributed as a fake Zoom installer disk image. The installer phishes the user's login password, uses it with sudo to launch a persistent daemon, and beacons a host survey to Cloudflare-fronted C2 over HTTPS. No threat actor attribution has been stated.

CloudSyncD is a macOS backdoor discovered by Jamf Threat Labs through VirusTotal monitoring. A first development build was seen on 2026-09-15; by 2026-09-17 related builds were configured with reachable C2 on two domains, indicating a move from development to deployment. Jamf published its analysis on 2026-09-30, and trade press followed on 2026-10-01 and 2026-10-02. Infosecurity Magazine notes that no confirmed infections were reported.

Delivery is a disk image (Zoom.dmg) that mounts as a volume named "Zoom" and contains an ad-hoc signed Zoom.app. Custom artwork in the image instructs the user to bypass Gatekeeper by manually approving the app in System Settings. The first-stage dropper (Zoom.app/Contents/MacOS/app_installer) shows a progress window reading "Downloading Zoom..." and an authorization dialog stating "Enter your password to allow this". It validates the supplied password against the local account using dscl.

The password is not exfiltrated. It is Base64-encoded with random padding (32-64 characters) and hidden in a decoy configuration file, ~/.config/zoom/data.json. Its offset and length are encoded as 48 invisible zero-width Unicode characters (U+200B and U+200C) in the "version" field. The dropper carries a complete universal Mach-O (about 756 KB in the development build) and extracts it at runtime. It first tries to execute the payload from an anonymous file descriptor (/dev/fd). When System Integrity Protection blocks that, it falls back to writing a temporary file, run via a .app_swap_<pid>.sh helper, and executing it with sudo using the harvested password.

The second stage installs under ~/.local/share/cloudsync/ (implant at appd, working tree .config/logs/) and runs under the process/daemon name cloudsyncd. Logs go to sync.err, encrypted with ChaCha20-Poly1305. Its C2 configuration is stored encrypted in the binary and decrypted at runtime. Jamf observed no LaunchAgent or LaunchDaemon persistence in the analyzed samples. Persistence is described as a persistent daemon. The implant collects a host survey (hwid, cpu_name, cpu_cores, ram, os, machine_name, user_name, mac, hw_model, ioreg output via /usr/sbin/ioreg -rd1 -c IOPlatformExpertDevice) and beacons every 8-16 seconds. Tasking delivers executables rather than shell commands: gzipped tar archives (extracted with /usr/bin/tar) or raw Mach-O files that are executed directly.

Two C2 domains, orchid-led[.]com and bjzhishang[.]com, were both registered in 2011 through the same registrar and sit behind Cloudflare. Both serve the identical URI path /macos/jquery.js so beacons resemble an ordinary JavaScript fetch. Every build shares the same string-obfuscation table, install paths, daemon name, process disguise, and C2 key/IV across builds. Code-signature build identifiers include main-arm64.out and cshelper. A development build pointed at a private-range endpoint (http://192.168.2.133:9099/ops) that was non-responsive during analysis.

MITRE ATT&CK techniques used in TL-2026-2840

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hidden Files and Directories

Discovery

T1033 System Owner/User Discovery; T1082 System Information Discovery

Credential Access

T1056.002 GUI Input Capture

Execution

T1059.004 Unix Shell; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography

Privilege Escalation

T1548.003 Sudo and Sudo Caching

defense-impairment

T1553.001 Gatekeeper Bypass

Affected products and versions in CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer

  • Apple — macOS (Apple silicon and Intel)
    Vulnerable versions: Hosts where a user runs the fake Zoom installer; universal Mach-O supports arm64 and x86_64

Remediation for CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer

Immediate actions

  • Hunt macOS endpoints for ~/.local/share/cloudsync/, ~/.config/zoom/data.json and a running process named cloudsyncd
  • Block orchid-led.com and bjzhishang.com and alert on HTTPS requests to /macos/jquery.js
  • If a host is affected, rotate the local account password and any credentials reused on that host, then reimage
  • Quarantine Zoom.dmg / Zoom.app/Contents/MacOS/app_installer matches by SHA256

Workarounds

  • Use EDR/MDM to block execution of ad-hoc signed applications launched from mounted disk images

Longer-term hardening

  • Keep Gatekeeper enforced and restrict users from approving unsigned or ad-hoc signed apps via MDM
  • Distribute Zoom only through managed channels or the official vendor site
  • Detect sudo executions of temp-written Mach-O files and writes under ~/.local/share and ~/.config by non-standard apps
  • Train users that macOS installers asking for a password after instructions to bypass Gatekeeper are malicious

Timeline of CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer

  • Jamf Threat Labs encounters the first CloudSyncD development build via VirusTotal monitoring; the build points at a private-range test endpoint.
  • Newer samples are found configured for reachable C2 on orchid-led[.]com and bjzhishang[.]com, indicating a shift from development to deployment.
  • Jamf's analysis reports no LaunchAgent/LaunchDaemon persistence and no built-in infostealer functionality (no browser data, Keychain or crypto-wallet collection) in the analyzed samples; the implant is a tasking backdoor that runs delivered executables.
  • Jamf publishes its technical analysis of CloudSyncD and the fake Zoom installer.
  • Infosecurity Magazine, Cyberpress, Cryptika and Hackread report on CloudSyncD; no confirmed infections are reported.
  • SecurityWeek reports that macOS users are targeted by the fake Zoom installer carrying the CloudSyncD backdoor.
  • BeaconBeagle config search for orchid-led.com and bjzhishang.com returns zero items, so no known beacon-config correlation exists for either C2 domain.

Sources cited for CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer

Detection coverage for TL-2026-2840

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2840 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats