macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
A macOS dropper has been found inside a disguised Zoom client. The malware is tracked as CloudSyncD and is designed to deliver a persistent and stealthy backdoor.
Researchers at Jamf first noticed this malware still in development in mid-September. Within days, other samples were found suggesting it has now progressed from testing and development to deployment.
The malware infection process is initiated by any of the standard social engineering methods designed to persuade or trick victims into downloading dangerous content. In this case it is malware hidden in malicious code disguised as a Zoom Mac installer. If the phish is successful, a malware dropper is delivered to the victim as a disk image that mounts as a volume named Zoom. This dropper contains the payload but must be activated by the victim – hence the disguise as a Zoom installer. The victim is guided through the activation thinking it will...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE