Macworld reported on 30 September 2026 that a newly identified threat for macOS arrives as a disk image presented as a Zoom installer, and that it runs on both M-series and Intel Macs [1]. The report credits Jamf Threat Labs with the discovery and gives the family the name CloudSyncD [1]. The installer relies on instructions that tell the user to bypass a macOS protection, which makes the user’s own action the entry point.
Background
Gatekeeper is the macOS check that refuses to open software that is not signed and approved in the usual way. Macworld notes that the installer includes background instructions on how to bypass Gatekeeper, which would otherwise block the software [1]. Jamf Threat Labs describes the same step: the disk image uses background artwork that instructs users to override Gatekeeper through System Settings [2].
What the reports describe
According to Macworld, the disk image imitates a standard Zoom installer with the usual drag-to-Applications layout. Macworld says the software reports to its operators as often as every 8 seconds and allows remote command execution, and it describes the family as an infostealer [1].
Jamf Threat Labs, the primary source, describes a disk image that mounts as a volume named “Zoom”, with an application icon on the left and an alias to Applications on the right [2]. Its first stage is an ad-hoc signed dropper that shows a password prompt reading “Enter your password to allow this” and then a progress window titled “Downloading Zoom…” [2]. The second stage is a universal Mach-O binary covering Apple silicon as well as Intel [2]. Jamf reports that it identified the development build on 15 September 2026 and, after two days of monitoring, found samples configured against live infrastructure on more than one command-and-control domain [2].
Implications for Mac users
The installer is not described as using a flaw in macOS. Macworld’s report and Jamf’s account both place the weight on a user being persuaded to override Gatekeeper and type a password [1] [2]. Mac users who obtain video-conferencing software from anywhere other than the vendor’s own site or the Mac App Store are the audience the reports address, and the architecture is no protection, since the software is reported to run on Intel Macs as well as Apple silicon [1].
Recommendations
- Download Zoom only from the Mac App Store or the vendor’s official website, as Macworld advises [1].
- Treat any disk image whose background tells you how to bypass Gatekeeper as a warning sign, since the reports describe exactly that instruction [1] [2].
- Do not type the Mac password into a prompt shown by a freshly downloaded installer.
- Verify sender addresses and URLs before clicking, and avoid links from unknown sources, as Macworld advises [1].
- Administrators using Jamf can configure threat prevention, advanced threat controls and web protection to Block and Report, as Jamf recommends [2].
Relevance to FireAI
FireAI is a network firewall for one Mac. It does not scan disk images, does not read installer artwork, does not stop a user from overriding Gatekeeper, and does not remove software that is already installed. It acts at the network layer: the first-connection prompt asks when an app or process reaches out to a destination for the first time, per-app rules can block it, and the Threats page lists what looks wrong. Software that repeatedly contacts a server, as the reports describe, is the kind of traffic these views would show, though the sources do not test FireAI against this family.
Limitations
Macworld and Jamf differ in emphasis. Macworld calls the family an infostealer, while Jamf states that the sample does not contain built-in features to collect browser data, keychain items or cryptocurrency wallets [1] [2]. The Macworld text retrieved for this item did not state how the installer is distributed to victims, and the number of affected Macs is not given in either source. Jamf’s analysis rests on a development build and samples configured for live infrastructure; behaviour of later builds is not established.
Try FireAI, by HisnLabs free for 17 days.