macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
According to Security Affairs, Jamf Threat Labs discovered CloudSyncD during routine VirusTotal scanning and found it concealing a phished password with invisible Unicode characters. SecurityWeek reports that the malicious installer contains a complete universal Mach-O executable, roughly 756 KB in its development build, which it extracts at runtime.
- Security Affairs reports researchers first spotted it on September 15, while it was still under construction.
Covered by 2 publishers within 26 hours of the first report.
Reporting2
SecurityWeek macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor · Kevin Townsend
Security Affairs Fake Zoom installer hides macOS backdoor CloudSyncD · Pierluigi Paganini
Related
Topics Apple