# CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer

> Jamf Threat Labs disclosed CloudSyncD, a two-stage universal Mach-O macOS backdoor distributed as a fake Zoom installer disk image. The installer phishes the user's login password, uses it with sudo to launch a persistent daemon, and beacons a host survey to Cloudflare-fronted C2 over HTTPS. No threat actor attribution has been stated.

- **Published:** 2026-10-02T00:00:00Z
- **Last reviewed:** 2026-10-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2840
- **ID:** TL-2026-2840
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CloudSyncD is a macOS backdoor discovered by Jamf Threat Labs through VirusTotal monitoring. A first development build was seen on 2026-09-15; by 2026-09-17 related builds were configured with reachable C2 on two domains, indicating a move from development to deployment. Jamf published its analysis on 2026-09-30, and trade press followed on 2026-10-01 and 2026-10-02. Infosecurity Magazine notes that no confirmed infections were reported.

Delivery is a disk image (Zoom.dmg) that mounts as a volume named "Zoom" and contains an ad-hoc signed Zoom.app. Custom artwork in the image instructs the user to bypass Gatekeeper by manually approving the app in System Settings. The first-stage dropper (Zoom.app/Contents/MacOS/app_installer) shows a progress window reading "Downloading Zoom..." and an authorization dialog stating "Enter your password to allow this". It validates the supplied password against the local account using dscl.

The password is not exfiltrated. It is Base64-encoded with random padding (32-64 characters) and hidden in a decoy configuration file, ~/.config/zoom/data.json. Its offset and length are encoded as 48 invisible zero-width Unicode characters (U+200B and U+200C) in the "version" field. The dropper carries a complete universal Mach-O (about 756 KB in the development build) and extracts it at runtime. It first tries to execute the payload from an anonymous file descriptor (/dev/fd). When System Integrity Protection blocks that, it falls back to writing a temporary file, run via a .app_swap_<pid>.sh helper, and executing it with sudo using the harvested password.

The second stage installs under ~/.local/share/cloudsync/ (implant at appd, working tree .config/logs/) and runs under the process/daemon name cloudsyncd. Logs go to sync.err, encrypted with ChaCha20-Poly1305. Its C2 configuration is stored encrypted in the binary and decrypted at runtime. Jamf observed no LaunchAgent or LaunchDaemon persistence in the analyzed samples. Persistence is described as a persistent daemon. The implant collects a host survey (hwid, cpu_name, cpu_cores, ram, os, machine_name, user_name, mac, hw_model, ioreg output via /usr/sbin/ioreg -rd1 -c IOPlatformExpertDevice) and beacons every 8-16 seconds. Tasking delivers executables rather than shell commands: gzipped tar archives (extracted with /usr/bin/tar) or raw Mach-O files that are executed directly.

Two C2 domains, orchid-led[.]com and bjzhishang[.]com, were both registered in 2011 through the same registrar and sit behind Cloudflare. Both serve the identical URI path /macos/jquery.js so beacons resemble an ordinary JavaScript fetch. Every build shares the same string-obfuscation table, install paths, daemon name, process disguise, and C2 key/IV across builds. Code-signature build identifiers include main-arm64.out and cshelper. A development build pointed at a private-range endpoint (http://192.168.2.133:9099/ops) that was non-responsive during analysis.

## MITRE ATT&CK

- T1204.002 Malicious File
- T1059.004 Unix Shell
- T1553.001 Gatekeeper Bypass
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1564.001 Hidden Files and Directories
- T1056.002 GUI Input Capture
- T1548.003 Sudo and Sudo Caching
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1071.001 Web Protocols
- T1573.001 Symmetric Cryptography
- T1132.001 Standard Encoding

## Sources

- [CloudSyncD: macOS backdoor hidden in a fake Zoom installer (Jamf Threat Labs)](https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/)
- [macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor (SecurityWeek)](https://www.securityweek.com/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/)
- [CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer (Infosecurity Magazine)](https://www.infosecurity-magazine.com/news/cloudsyncd-macos-backdoor-fake/)
- [Fake Zoom Installer Deploys CloudSyncD macOS Backdoor and Hides Password in Zero-Width Unicode (Cyberpress)](https://cyberpress.org/fake-zoom-drops-cloudsyncd-backdoor/)
- [Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor (Cryptika)](https://www.cryptika.com/fake-zoom-installer-tricks-mac-users-into-installing-new-cloudsyncd-backdoor/)
- [New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords (Hackread)](https://hackread.com/cloudsyncd-macos-backdoor-fake-zoom-installer-passwords/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2840
