macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

First reported by SecurityWeek at · Updated · 2 sources

According to Security Affairs, Jamf Threat Labs discovered CloudSyncD during routine VirusTotal scanning and found it concealing a phished password with invisible Unicode characters. SecurityWeek reports that the malicious installer contains a complete universal Mach-O executable, roughly 756 KB in its development build, which it extracts at runtime.

  • Security Affairs reports researchers first spotted it on September 15, while it was still under construction.

Covered by 2 publishers within 26 hours of the first report.

Reporting2

Security Affairs Fake Zoom installer hides macOS backdoor CloudSyncD · Pierluigi Paganini

Related

Topics Apple