Guide

Fake Zoom Installer Drops CloudSyncD Mac Backdoor That Hides Passwords in Invisible Unicode

A new macOS backdoor called CloudSyncD is spreading as a fake Zoom installer, and its most unsettling trick is invisible. After stealing a victim's Mac

A new macOS backdoor called CloudSyncD is spreading as a fake Zoom installer, and its most unsettling trick is invisible. After stealing a victim's Mac password, it hides that password using Unicode characters that don't render on screen at all.

Jamf Threat Labs uncovered the malware, which first showed up on VirusTotal around September 15. Those early samples looked like works in progress. Later builds were fully operational, talking to live command-and-control servers across more than one domain.

Talking users past Gatekeeper

The attack starts with a disk image that mounts as a volume named "Zoom." Rather than exploiting a flaw, it simply coaches the victim through disabling Apple's protections, walking them to the "Open Anyway" button in System Settings to override Gatekeeper.

Then comes a fake password prompt. CloudSyncD checks the entered password against the system with the dscl utility, so it knows it has the real thing, while a convincing fake download progress window keeps the victim waiting patiently.

It's the same lesson as the Milk Dragon phishing kits that bypass MFA: the weakest point is often the person being politely asked to type a secret.

A password hidden in plain sight

The stolen password gets written to ~/.config/zoom/data.json, a path designed to look like harmless app settings. Inside, it sits in a cache value as base64, padded with random filler, researchers found.

The clever part is how operators find it again. The malware encodes the password's length and offset inside the file's version field using zero-width characters, specifically U+200C (zero-width non-joiner) and U+200B (zero-width space). Open the file and the version looks normal. Scan the logs and there's no obvious plaintext to flag.

That kind of stealthy persistence echoes the self-healing WordPress backdoor defenders have been chasing, where the malware's goal is simply to look like it belongs.

Second stage, full control

With a validated password in hand, CloudSyncD uses it to elevate a second-stage payload. That payload is a universal Mach-O binary, meaning it runs natively on both Apple silicon and older Intel Macs.

The upshot is a backdoor with admin rights, no exploit required, built entirely on a user trusting a familiar logo. Zoom installers only come from Zoom's own site, and no legitimate one needs you to override Gatekeeper.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free