New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
Cybersecurity researchers at Jamf Threat Labs have identified CloudSyncD, a previously undocumented macOS backdoor distributed through a malicious disk image disguised as a Zoom installer.
The malware’s custom artwork instructs users to bypass macOS Gatekeeper, a security feature that blocks unverified applications, by manually approving the software through System Settings.
This research, shared with Hackread.com, details how the malware tricks users into revealing their passwords and uses the credentials to launch the second stage on their Macs.
Fake Authorization Prompt Conceals Password
Once launched, the first-stage binary, app_installer, displays a fake authorization prompt asking users to enter their password. The malware validates the password against the local account using the macOS directory service utility dscl. A fake “Downloading Zoom…” window then appears.
Rather than sending the credential to attackers, the malware stores it in ~/.config/zoom/data.json, disguised as a normal application configuration file. It base64-encodes the password and hides it...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE