CloudSyncD macOS backdoor hides in fake Zoom installer

CloudSyncD macOS backdoor hides in fake Zoom installer

A newly documented macOS backdoor called CloudSyncD is reaching victims through a fake Zoom installer, according to researchers at Jamf. The malware gives attackers persistent, quiet access to infected Macs.

Jamf first came across CloudSyncD in mid-September, while it was still under development. Within a few days the researchers found more samples. These suggested the operators had finished testing and begun using the malware against real targets.

A disk image posing as Zoom

The attack depends on social engineering. Victims are persuaded or tricked into downloading what looks like a Zoom installer for Mac. If they fall for it, they receive a disk image that mounts as a volume named Zoom.

The disk image contains a dropper, and the payload is packed inside it. Nothing happens until the victim launches the dropper, which explains the Zoom disguise. The victim is walked through what appears to be a normal Zoom setup, but the process installs CloudSyncD instead.

According to the researchers, the dropper "carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime." A second copy of the payload sits on disk inside the application bundle, so the dropper can pull it from either location.

Falling back on the user's password

The dropper first writes the payload to an anonymous file descriptor and tries to run it from there without touching the disk. In most cases this fails because of macOS System Integrity Protection (SIP), the built-in feature that restricts what software can modify on the system.

When that happens, the dropper writes the file to disk for a short time and runs it with sudo. It uses the password the victim typed in during the fake installation, which gives the backdoor root privileges.

CloudSyncD keeps its configuration encrypted inside the binary and decrypts it only at runtime. It runs as a daemon named CloudSyncD.

From test build to live campaign

The first sample Jamf analyzed was clearly not ready for use. Its command-and-control (C2) address pointed to a private network, and verbose debug logging was still turned on.

That has since changed. The researchers found several builds communicating with two separate domains. Both use the same URI path, which is made to look like a jQuery script so that the malware's beacon resembles an ordinary JavaScript request. The two domains were registered in 2011 through the same registrar and sit behind Cloudflare. Neither was flagged by security vendors when the research was published.

The builds also share a lot of internal material. "Every build shares the same string obfuscation table, the same install paths, daemon name and process disguise, and, more tellingly, the same C2 key and initialization vector, down to the identical per-string seeds," the researchers said. "Only the endpoint changes. Captured beacon traffic is therefore decryptable with material recovered from any build, and the on-host indicators hold across all of them."

A backdoor, not a stealer

The way CloudSyncD is delivered resembles a typical infostealer campaign, but its function is different. It has no standard data-stealing features. The password it collects is not sent to the attackers and is used only on the device to gain root access.

The backdoor profiles the host, carries out reconnaissance and sends system and user details to its C2 server. Its main job is to keep long-term access open so the attackers can deploy additional payloads later.

Because the malware is now in active use, Jamf has published a long list of indicators of compromise (IOCs) for defenders to track.

Our take

CloudSyncD follows a pattern we have seen across recent Mac threats. The code is native, its strings are protected, and it tries to avoid writing payloads to disk. Yet it still relies on the oldest trick there is, which is getting the user to type in their password. The same mix showed up recently in MacSync malware, which also leaned on fake apps and password prompts.

For organizations, the practical lesson is simple. Video conferencing apps should come from official sources or managed deployment tools, and staff should be wary of any installer that asks for an admin password in an unexpected context. Keeping systems patched, as with Apple's recent CoreGraphics zero-day fix, matters too, although it does not stop an attack that depends on a user handing over credentials.

The reused C2 key across builds is a real gift to defenders, since it lets them decrypt captured traffic. It is worth watching whether the operators fix this weakness in later versions, and what follow-up payloads they eventually push to the Macs they already control.