Fake Zoom installer for Mac spreads CloudSyncD backdoor
A new macOS backdoor named CloudSyncD has been discovered hidden in a fake Zoom installer, according to Jamf. The installer instructs users to bypass Apple's built-in security and prompts for their system password. This password is used to launch a malicious payload with elevated rights. The malware establishes encrypted contact with a remote server to execute commands or run files. No confirmed infections have been reported so far.
- Malware disguises as a Zoom installer disk image
- Instructs users to override macOS security warnings
- Harvests password for privilege escalation, not theft
- Backdoor can receive commands and execute remote code
- Jamf found no evidence of widespread infection
Sources covering this
In this story
More in Cybersecurity
Police arrest alleged 16-year-old leader of KillSec ransomware group
An international law enforcement operation has arrested a 16-year-old suspected of leading the KillSec ransomware gang, seized its leak…
New device claims to freeze iPhones to bypass Apple security
A leaked video shows Magnet Forensics, seller of the popular GrayKey hacking tool, claiming its new device can bypass Apple's 72-hour…
Chinese hackers targeted AI policy experts with phishing
Researchers report that a China-linked hacking group used phishing emails to impersonate AI experts and policy officials, targeting…
GrayKey tool reportedly bypasses iPhone Inactivity Reboot
GrayKey, a forensic tool from Magnet Forensics, can reportedly bypass the iPhone's Inactivity Reboot feature, which is designed to…