Fake Zoom Installer Drops CloudSyncD Backdoor

Security Week Feed · Medium sophistication
Last updated October 5, 2026

Researchers found macOS users being tricked into installing a fake Zoom app that actually installs a persistent backdoor called CloudSyncD. The installer guides the victim through a normal-looking setup and prompts for the user’s password so it can run with elevated privileges and stay on the Mac long term.

How the attack worked

Attackers distributed a macOS installer disguised as Zoom. When opened, the disk image mounts as a volume named Zoom and walks the victim through what appears to be a routine installation process. Instead of installing the real conferencing app, the process installs a persistent backdoor called CloudSyncD. The dropper is designed to only trigger when the victim actively participates in the activation steps, which is why the disguise as a familiar, trusted app like Zoom matters so much to the attacker.

The password prompt is the real trap

A central part of this attack is a prompt for the user's macOS password during what looks like a normal app setup. The dropper uses that password with sudo to write and execute the payload to disk when direct execution would otherwise be blocked by macOS security protections. This step depends entirely on the victim treating the password request as a normal part of installing Zoom rather than recognizing it as unusual.

Why it succeeds

This campaign relies on standard social engineering rather than a technical exploit of Zoom itself. The installer looks and behaves enough like a legitimate setup flow that victims proceed through each step, including entering credentials, without pausing to question the source. Once CloudSyncD is installed, it establishes persistence through a daemon and communicates with attacker infrastructure while disguising its traffic to resemble an ordinary JavaScript fetch, such as a jQuery script, making the activity harder to flag through casual observation of network behavior.

What to watch for

  • Installers obtained from sources other than the official vendor site, App Store, or an approved internal software portal
  • Any unexpected request to enter your macOS password during what should be a simple app installation
  • Disk images or installer behavior that doesn't match the normal, known installation flow for an app like Zoom
  • Unusual background network activity that resembles common scripts but originates from a newly installed app

Building resistance

Organizations can reduce exposure by reinforcing a few habits across all macOS users, not just technical staff. Employees should be trained to install common software only from approved sources and to treat any install-time password prompt as a signal to pause and verify with IT before continuing. Because this technique still depends on tricking a person into handing over a password, awareness training that specifically covers fake installer scenarios, combined with clear reporting channels for suspicious downloads, directly addresses the weak point this campaign exploits across finance, HR, executive, and general staff roles alike.

Key findings

  • Malware was delivered as a Zoom-branded macOS installer (disk image) to trick users into running it.
  • The mounted disk image appears as a volume named "Zoom" and the user is guided through activation as if installing Zoom.
  • The dropper can prompt for the user’s password and use it with sudo to execute the payload when macOS protections block direct execution.
  • CloudSyncD establishes persistence via a daemon and communicates with attacker-controlled infrastructure while trying to look like normal web traffic.
  • The campaign progressed from development/testing to active deployment across multiple domains.

Who’s being targeted

  • Commonly targeted roles: All employees (macOS users), IT/Helpdesk, Executives/Assistants, Finance, HR.
  • Affected industries: Any organization with macOS users (cross-industry).
  • Attack channels: website.
  • Impersonated: Zoom (fake Zoom Mac installer).

Red flags to watch for

  • Installer obtained from an untrusted/non-official download source
  • Unexpected prompt to enter your password during a basic app install
  • Disk image/installer behavior doesn’t match normal Zoom installation (e.g., odd prompts, unusual volume/app details)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake Zoom installer infect a Mac?

The malware is delivered as a disk image that mounts as a volume named Zoom, guiding the victim through what looks like a normal installation while actually installing the CloudSyncD backdoor.

Why does the fake installer ask for my password?

The dropper prompts for the user's macOS password so it can use sudo to execute the payload with elevated privileges when normal execution is blocked by macOS protections.

How does CloudSyncD stay hidden on an infected Mac?

It establishes persistence through a daemon and communicates with attacker-controlled infrastructure by masquerading as a jQuery script so its network traffic resembles an ordinary JavaScript fetch.

Who is at risk from this campaign?

Any organization with macOS users is affected, including all employees, IT and helpdesk staff, executives, finance, and HR.

Read the video transcript

You’re on a website that says, “Download Zoom for Mac (Installer).” Looks normal, right? This is where the trap starts. You download a Zoom-branded disk image. It mounts as a volume named “Zoom,” walks you through a normal-looking setup, then suddenly asks for your macOS password to ‘complete activation.’ That’s the CloudSyncD backdoor installer, not Zoom. Type your password there, and the dropper uses sudo to plant a persistent daemon called CloudSyncD. It phones home over the network, masquerading as normal web traffic, like a jQuery script quietly fetching data in the background. Here’s the move: if you’re installing Zoom or any common app and see an unexpected password prompt, stop and don’t type it, contact IT and ask, “Is this installer legit?”

Similar attacks

Fake LastPass App on GitHub Drops Rapuncel Stealer

Fake LastPass App on GitHub Drops Rapuncel Stealer

Attackers used fake “LastPass Authenticator” and fake macOS LastPass pages on GitHub to trick people into downloading a malicious installer. The campaign relied on SEO so the fraudulent GitHub page appeared near the top of search results, then redirected victims through multiple pages to a download…

September 21, 2026
Fake IRS Letters and BoA Emails Push Remote Access Scams

Fake IRS Letters and BoA Emails Push Remote Access Scams

This weekly roundup includes real-world social engineering campaigns, including scammers mailing fake IRS letters to cryptocurrency holders and a phishing campaign impersonating Bank of America. The lures are designed to pressure victims into visiting a bogus compliance portal or installing remote…

August 9, 2026
Fake Zoom Updates Install ScreenConnect Backdoor

Fake Zoom Updates Install ScreenConnect Backdoor

Researchers describe an active campaign ("SMOKE#SCREEN") where attackers trick users with realistic software update and document-themed lures to install a legitimate remote-control tool (ScreenConnect). Once installed, the attacker gains persistent remote access that can look like normal IT…

August 5, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Fake Zoom Installer Tricks Mac Users for Password

Fake Zoom Installer Tricks Mac Users for Password

Researchers found a malicious macOS app disguised as a Zoom installer. It walks users through bypassing macOS security prompts, then repeatedly asks for the user’s password to ‘continue installation’ until the correct password is entered. The stolen password is hidden inside a fake settings file…

October 3, 2026
China-Linked Phish Uses Fake Gmail Preview

China-Linked Phish Uses Fake Gmail Preview

A China-linked espionage group (UAT-11587) targeted Asian government and policy organizations using highly tailored phishing emails and realistic decoy documents. After a click, malware ultimately installed the “Antino” backdoor, which then hid its command-and-control traffic inside normal…

October 3, 2026