Security & AI news

macOS backdoors · By FireAI Security & Research Team · Published

Jamf Threat Labs analyses CloudSyncD, a two-stage macOS backdoor that hides a phished password in zero-width Unicode

Jamf Threat Labs’ 30 September 2026 analysis of CloudSyncD: a fake Zoom dropper, a password hidden in a settings file, and a second-stage beacon.

An eye over a line of hidden characters and the FireAI detective mascot, illustrating Jamf Threat Labs’ analysis of a macOS backdoor that hides a phished password in zero-width Unicode.

Jamf Threat Labs published an analysis of CloudSyncD on 30 September 2026. It describes a two-stage macOS backdoor delivered through a fake Zoom disk image, which asks for the user’s password, stores it in an obfuscated settings file and then runs a second stage that checks in with a server [1]. Jamf states that its researchers identified the family on 15 September 2026 in a development build, and that after two days of monitoring they found samples configured against live infrastructure [1].

Background

A dropper is a first-stage program whose job is to install a second one. Jamf reports that the disk image mounts as a volume named “Zoom” and imitates a macOS installer, with background artwork that tells users how to bypass Gatekeeper in System Settings [1]. Macworld covered the same family on 30 September 2026, crediting Jamf Threat Labs [2].

What the report describes

Stage 1. The dropper is located at Zoom.app/Contents/MacOS/app_installer and is ad-hoc signed. An Objective-C class named AuthDialog shows the credential prompt “Enter your password to allow this”, the password is checked locally with the dscl command, and a fake progress window reads “Downloading Zoom…” [1].

Password handling. The dropper writes the captured password to ~/.config/zoom/data.json, where it resembles application settings. The password is base64 encoded, buried inside a long cache value and padded on both sides with between 32 and 64 random characters. The visible version string “1.0.0” is followed by 48 zero-width Unicode characters (U+200B and U+200C) that encode the offset and length of the payload, and neither character renders on screen [1]. Jamf states that the password is never recorded or sent anywhere [1].

Execution. The dropper first writes the payload to an anonymous file descriptor and tries to execute it through /dev/fd, presumably to avoid writing the binary to disk. In Jamf’s testing this failed with the log line “/dev/fd spawn failed rc=13”. The fallback uses sudo with the harvested password to run the second stage from disk [1].

Stage 2. The implant, named after the cloudsyncd daemon name, is a universal Mach-O that covers Apple silicon as well as Intel and is ad-hoc signed, at approximately 756 KB in the development build. It reads the hardware UUID with ioreg, writes an encrypted log (ChaCha20-Poly1305) to a sync.err file, sends a host survey of just under 2 KB and then repeats check-ins carrying only the hardware UUID, every 8 to 16 seconds [1]. A reply may carry a task: gzipped tar archives are unpacked with /usr/bin/tar, raw Mach-O files are executed, and other formats are discarded [1].

Infrastructure. Jamf identified two active command-and-control domains at publication, both registered in 2011 through the same registrar and behind Cloudflare, with request paths made to look like a jQuery script. The samples share the same key and initialisation vector. Jamf observed no LaunchAgent or LaunchDaemon in the development testing, that is, no persistence mechanism [1].

Implications for Mac users

Jamf’s assessment is that infostealers may dominate the threat landscape, yet attackers still have use for quieter software that lies low until further access is needed, and that this family depends on the oldest technique available: asking the user for a password [1]. The user’s own steps, overriding Gatekeeper and typing the password, are what make the second stage run. Macworld reports that the family affects both M-series and Intel Macs [2].

Recommendations

  1. Install Zoom only from the Mac App Store or the vendor’s official website [2].
  2. Do not follow background-artwork instructions on a disk image that tell you to override Gatekeeper [1].
  3. Do not enter the Mac password into a prompt from a freshly downloaded installer.
  4. If such an installer was opened and a password entered, check for ~/.config/zoom/data.json and ~/.local/share/cloudsync, both paths named in Jamf’s analysis, and ask an administrator or a security professional for help [1].
  5. Administrators using Jamf can set threat prevention, advanced threat controls and web protection to Block and Report [1].

Relevance to FireAI

FireAI is a network firewall for one Mac. It does not open disk images, does not read file contents, does not detect hidden Unicode, does not prevent a user from entering a password and does not delete files. Its role is the connection that comes after: the first-connection prompt asks when a process contacts a destination for the first time, per-app rules can block it, investigate a connection shows details, and the kill switch refuses new connections. A repeating check-in of the kind Jamf describes would show as recurring traffic from one process. Jamf did not test FireAI.

Limitations

The analysis is Jamf’s, and the technical details come from a development build plus samples that Jamf describes as configured for live infrastructure. The report says the build placed no binary at its configured path and used no persistence, so later builds may differ. Macworld describes the family as an infostealer and Jamf states there are no built-in features to collect browser data, keychain items or cryptocurrency wallets [1] [2]. The number of victims and the route by which victims reach the disk image are not given in the sources retrieved.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. Jamf Threat Labs, 30 September 2026: CloudSyncD, a two-stage macOS backdoor that hides a phished password in zero-width Unicode
  2. Macworld (Roman Loyola), 30 September 2026: New macOS malware masquerades as Zoom installer