Researchers found CloudSyncD hidden inside a fake Zoom macOS installer, where it uses social engineering to trick victims into entering their password and launching the malware. The campaign has moved from testing to deployment, delivering a persistent backdoor that profiles the host, communicates with C2 infrastructure, and avoids traditional infostealer behavior. #CloudSyncD #Zoom #Jamf
Keypoints
- CloudSyncD is a macOS dropper disguised as a Zoom installer.
- The malware uses social engineering to obtain the victimβs password.
- Researchers first observed it in development, then later in active deployment.
- CloudSyncD installs a persistent backdoor for long-term access and reconnaissance.
- Its builds share the same obfuscation, install paths, daemon name, and C2 encryption material.