Jamf Threat Labs has published an analysis of CloudSyncD, a two-stage macOS backdoor delivered as a fake Zoom installer. In its report dated September 30, 2026, Jamf says it first saw the malware on September 15 in a build still under development. Two days of monitoring turned up samples configured against live command-and-control infrastructure on more than one domain, which Jamf reads as the operators moving from testing toward deployment.

The disk image mounts as a volume named Zoom. Its artwork tells the victim to click Open Anyway under Privacy and Security and enter an administrator password, which overrides macOS Gatekeeper for an app that is only ad-hoc signed. The first stage then shows a fake authorization prompt and checks the password against the local account. Jamf says the second stage is carried inside the first, and the dropper launches it with sudo using the password the victim typed.

Jamf says it looks like an infostealer at first glance but is not. The password is never recorded or sent anywhere, and the malware has no built-in features to collect browser data, keychain items or cryptocurrency wallets. The implant beacons to its server and can receive tasks delivered as executables. Jamf did not see it establish persistence in its tests.

Why it matters: the password prompt is there to get root, not to be stolen. Our read: detection tuned to credential theft will miss this one. The signals Jamf describes sit earlier and later in the chain, a user overriding Gatekeeper for a disk image styled as Zoom, and an unsigned app running a second binary through sudo. Both are worth a help desk alert and a line in user awareness training. We covered a similar fake-installer approach in a fake crypto wallet that hides Mac malware in iCloud and fake Codex ads that now impersonate Claude Code.

Jamf publishes file hashes and a VirusTotal collection with the report.

Source: Jamf Threat Labs, CloudSyncD