DEV Community

Anoymask
Anoymask

Posted on

CloudSyncD: Fake Zoom Installer Hides a Stolen Password with Zero-Width Unicode and Launches a macOS Backdoor

1. Basic Information

  • Original Title: CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode
  • Source: Jamf Threat Labs
  • Publication Date: 2026-09-30
  • Update Date: None
  • Severity: High
  • Basis of Severity: The demonstrated infection chain requires the victim to override Gatekeeper and enter the correct password for a local account authorized to launch stage 2 as root via sudo. Jamf observed backdoor execution and C2 beaconing. The implant can execute additional payloads, but no remote task delivery was observed during analysis. Multiple builds configured to use reachable C2 endpoints were identified; affected organizations and the extent of compromise in the wild remain unknown.
  • Source Link: Jamf Threat Labs
  • Related Sources: SecurityWeek, MITRE ATT&CK: GUI Input Capture, MITRE ATT&CK: Sudo and Sudo Caching
  • Related Malware: CloudSyncD
  • Related Threat Groups: None
  • Related CVEs: None
  • Related Products: macOS, Zoom (impersonated)

2. Executive Summary

CloudSyncD uses a Zoom-impersonating disk image to prompt users to bypass Gatekeeper and enter their administrator password. It indexes the password using zero-width Unicode and conceals it inside a decoy JSON file. The captured password is then passed to sudo to execute an embedded Mach-O backdoor with root privileges and send host information. While it includes functionality to receive and execute additional payloads, Jamf did not observe any remote task delivery during its analysis.

3. Attack Flow

Flow 1: From Fake Zoom to CloudSyncD Stage 2 Execution

  1. The victim mounts a disk image disguised as Zoom and manually bypasses Gatekeeper by following instructions in the background image.
  2. After the user enters a password into the fake authentication prompt, the dropper verifies it using the dscl command and conceals it inside a decoy data.json file using zero-width Unicode indexing.
  3. The dropper attempts to execute the embedded Mach-O binary from /dev/fd, falling back to writing it to a temporary file if that fails.
  4. It passes the stolen password to sudo and launches the stage 2 implant with root privileges.

Flow 2: C2 Communication and Task Processing After Stage 2 Launch

  1. The implant sends host reconnaissance data, including the hardware UUID, CPU, RAM, OS, and username, to the C2 server.
  2. It checks in with /macos/jquery.js every 8 to 16 seconds.
  3. If the C2 response contains a task, the implant decrypts it and executes either the extracted executable from a gzip tar archive or a raw Mach-O file directly. No remote tasks were delivered, and execution at this stage was not observed during Jamf's analysis.

4. Attacker Position and Execution Environment

  • In the initial stage, the attacker delivers the fake disk image to the victim. The specific delivery channel has not been publicly disclosed.
  • Stage 2 connects to a C2 server behind Cloudflare and is configured to receive tasks, though no remote task delivery was observed during Jamf's analysis.

5. Visibility for Victims and Administrators

Victims

  • Victims see a Zoom-themed disk image and setup instructions, the Open Anyway action, a fake authentication dialog, and a Downloading Zoom message.

Administrators

  • Artifacts include an ad-hoc signed Zoom.app, dscl authonly, temporary Mach-O binary execution via sudo -S, a decoy data.json file, ~/.local/share/cloudsync/.config/logs/sync.err, and C2 traffic to /macos/jquery.js. The data.json file is located at ~/.config/zoom/ in development builds and ~/.config/cloudsync/ in live builds. Renaming the process to cloudsyncd was not observed.

6. Success and Failure Conditions

Success Conditions

  • The victim runs the fake Zoom installer and manually bypasses Gatekeeper.
  • The entered local account password is correct, and that account has sudo privileges capable of launching stage 2 with root privileges. Successful password verification alone does not guarantee root-privilege execution.
  • The embedded stage 2 successfully launches via sudo. Sending information to the C2 and receiving additional tasks requires further C2 reachability, and blocking C2 communication alone does not negate the execution of stage 2 on the endpoint.

Failure Conditions

  • Blocking the execution of Zoom installers from unofficial sources and preventing Gatekeeper bypass actions.
  • MDM or EDR solutions preventing ad-hoc signed apps, password verification via dscl, and sudo execution of unknown binaries.
  • Monitor and block connections to known C2 servers or newly registered or low-reputation domains, correlating each connection with the process that initiated it.

7. What Happens Upon Success

  • Execution of the CloudSyncD backdoor with root privileges.
  • Transmission of host profile information to the C2 server.
  • Capability to receive and execute additional Mach-O payloads through C2 tasks; neither task delivery nor additional payload execution was observed during Jamf's analysis.
  • Local exposure of the captured password due to it being concealed in a decoy JSON file with 0644 permissions.

8. Observable Logs

Email

  • Specific email campaigns have not been disclosed. Check for fake Zoom URLs or DMG attachments if present.

Proxy / SWG / DNS

  • Look for access to orchid-led[.]com, bjzhishang[.]com, and /macos/jquery.js.

Endpoint / EDR

  • Verify /Volumes/Zoom, app_installer, dscl -authonly, sudo -S, .s_ temp files, data.json, the cloudsync directory, and Mach-O execution.

Identity / IdP

  • Focuses on local password entry and verification. If password reuse is suspected, review IdP sign-in history as well.

SaaS / Cloud

  • Combine available MDM application inventory with endpoint telemetry, such as EDR records, to identify Gatekeeper overrides or suspicious application execution. MDM alone may not record individual executions or overrides.

Network

  • Monitor for C2 beacons at 8 to 16-second intervals, initial reconnaissance data transmission of approximately 2 KB, and subsequent check-in traffic centered around the hardware UUID.

9. Attack Success Determination

Confirm User Interaction

  • Public Information and Criteria: Public Information: Infection requires bypassing Gatekeeper and entering a correct password. Criteria: Confirm execution of the fake Zoom app, the Open Anyway action, verification via dscl, or the creation of data.json. Simply downloading the DMG does not constitute a successful infection.
  • Scope: Fake Zoom dropper
  • Related CVEs: None

Confirm Malware Execution or Authentication Success

  • Public Information and Criteria: Public Information: Jamf observed stage 2 launching in a sandbox environment and beaconing to an active C2 server. Criteria: Confirm sudo execution of the embedded Mach-O binary, cloudsync-related artifacts, and check-in traffic to the C2.
  • Scope: CloudSyncD stage 2
  • Related CVEs: None

Confirm Subsequent Compromise

  • Public Information and Criteria: Public Information: While functionality to execute additional Mach-O binaries from C2 tasks exists, no remote task delivery was observed during Jamf's analysis. Criteria: Correlate task responses, decrypted and extracted executables, and actual process execution. Beacons or payload writes alone do not confirm successful secondary execution.
  • Scope: Additional payloads delivered via C2 tasks
  • Related CVEs: None

10. Investigation Playbook

Trigger

  • Trigger on fake Zoom apps, Gatekeeper overrides, dscl authonly, sudo execution of .s_ files, cloudsync-related artifacts, and C2 domains.

Initial Verification

  • Verify the DMG source, executing user, password input, Gatekeeper events, EDR/MDM coverage, and C2 reachability.

Endpoint

  • Preserve the DMG, application bundle, data.json, temporary files, the cloudsync tree, sync.err, process memory, modules, and hash values.

Identity and Cloud

  • Evaluate potential reuse of the entered password and check for sign-ins to IdPs, VPNs, or SaaS applications that use the same credentials as the local account.

Subsequent Actions

  • Track C2 responses, downloaded Mach-O binaries, persistence settings, browser and keychain access, and lateral movement.

Containment

  • Isolate the endpoint and preserve evidence, then remove the malware or reimage the device using a clean system image. Change passwords from a trusted device.

Decision Categories

  • Differentiate and log lure viewing, Gatekeeper bypass, password verification, stage 2 execution, C2 communication, and subsequent payload execution.

11. Defense and Detection Ideas

Single Event

  • Alert on unknown applications passing passwords via arguments to dscl -authonly, or events launching .s_ temporary files via sudo -S --preserve-env.

Temporal Correlation

  • Correlate Zoom DMG mounting -> Gatekeeper override -> dscl execution -> data.json creation -> sudo execution -> C2 beaconing as a single sequence of events.

Hunting Perspective

  • Search for JSON files containing U+200B/U+200C characters, cloudsync-related paths, sync.err, C2 encryption keys/IVs, the two reported C2 domains, and public hash values.

Log Gaps

  • Jamf did not observe persistence being established or the process being renamed to cloudsyncd. In testing, the /dev/fd execution attempt failed and the dropper used a temporary-file fallback. The absence of LaunchAgents, a process named cloudsyncd, or /dev/fd execution records does not rule out infection.

Priority Mitigations

  • Prioritize distributing official Zoom installers, enforcing Gatekeeper and MDM policies, deploying behavioral EDR solutions, blocking C2 communication, and having users change their passwords.

12. Facts, Inference, and Hypothesis

Facts

  • CloudSyncD is distributed via a disk image disguised as Zoom, which prompts users to perform a Gatekeeper Open Anyway action and enter their administrator password by following instructions in the background image.
  • The dropper locally verifies the entered password using dscl, Base64-encodes it, embeds it into a random string, and saves it in a data.json file with offsets and lengths encoded using zero-width Unicode. The analyzed dropper does not exfiltrate the password externally but uses it to execute stage 2 via sudo, while leaving it locally recoverable. The storage path is ~/.config/zoom/ for development builds and ~/.config/cloudsync/ for live builds.
  • The dropper contains a universal Mach-O stage 2 payload and first attempts to launch it through /dev/fd. Jamf reported that this attempt failed in testing and attributed the failure to SIP. The dropper then wrote the payload to a temporary file and launched it via sudo.
  • Production builds beacon to /macos/jquery[.]js on orchid-led[.]com or bjzhishang[.]com and transmit host reconnaissance data. While functionality exists to decrypt tasks and either extract gzip tar archives or execute raw Mach-O files, no remote task delivery was observed during Jamf's analysis.
  • Jamf did not observe the executed builds placing files into the configured installation path or establishing persistence via LaunchAgents or LaunchDaemons. While backdoor functionality and daemon names exist, successful persistence has not been confirmed.
  • The builds analyzed by Jamf share C2 encryption keys/IVs and string obfuscation tables, which can be used to decrypt captured traffic and correlate samples. This may not apply to all unanalyzed variants.

Inference

  • Zero-width Unicode characters in data.json and command-line arguments for dscl/sudo serve as high-precision threat hunting indicators even for builds with changing hash values.
  • The appearance of the fake Zoom UI does not indicate a successful infection. Verification of the correct password, sudo execution, C2 beaconing, and task execution must be confirmed step-by-step.

Hypothesis

No additional hypotheses. Unverified items are listed in section 14, Unresolved Questions and Further Investigation.

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1036 Masquerading high Impersonates Zoom disk images and applications. While a daemon/process name of cloudsyncd exists in the configuration, process renaming at runtime was not observed.
T1056.002 Input Capture: GUI Input Capture high Captures the local account password via a fake authentication dialog.
T1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo Caching high Passes the captured password to the standard input of sudo -S to launch stage 2. Distinct from abusing the AuthorizationExecuteWithPrivileges API.
T1059.004 Command and Scripting Interpreter: Unix Shell high Execution utilizing shell scripts, sh -c, and sudo was confirmed during analysis.
T1105 Ingress Tool Transfer high Mapped to the capability to receive additional executables from C2 tasks. Neither remote task delivery nor additional payload execution was observed during analysis.
T1082 System Information Discovery high Collects CPU, RAM, OS, hardware UUID, and other details via sysctl/ioreg.

14. Unresolved Questions and Further Investigation

  • The actual initial delivery campaign, targeted organizations, and scale of impact.
  • Subsequent payloads delivered via C2 tasks and their ultimate objectives.
  • Whether the configured persistence mechanism successfully functions in other environments.

15. Impact on SOCs and Organizations

For macOS users in Japanese organizations, a fake Zoom installer can be a convincing lure. Use MDM to restrict Gatekeeper bypass actions and ad-hoc signed applications, and standardize Zoom deployment through official channels. SOC teams should not stop investigations at password theft, but should track sudo execution, temporary Mach-O binaries, C2 communication, and secondary tasks through to completion.

16. Summary by Role

  • SOC: Correlate data.json files containing zero-width Unicode, dscl authonly, sudo execution of .s_ temporary files, cloudsync-related paths, and the two C2 domains during investigations.
  • Administrators: Distribute Zoom through official channels, enforce Gatekeeper and MDM policies, restrict ad-hoc signed applications, and hunt for signs of compromise on Macs using published IoCs and behavioral telemetry.
  • Users: Install Zoom only from the official portal or internal distribution systems. If an unknown installer prompts you to bypass security protections via Open Anyway or requests your password, stop the process and report it to your administrator. A password prompt alone does not automatically designate an installer as malicious.

Top comments (0)