Recommended Free Tools
CloudSyncD is a macOS backdoor delivered through a fake Zoom-branded disk image, not through the legitimate Zoom app or Zoom’s systems, according to Jamf Threat Labs. Its installer tries to persuade users to override Gatekeeper and enter their Mac account password.
Is this really the Zoom app?
No. Jamf Threat Labs’ September 30, 2026 report describes a fake Zoom-branded installer. The report does not say that the legitimate Zoom app or Zoom’s systems distributed CloudSyncD. The technical findings concern samples Jamf analyzed, not a measured count of infected users.
Jamf says it first found the malware during routine VirusTotal monitoring on September 15, 2026. The sample appeared to still be under development; after two days of monitoring, researchers identified samples configured to communicate with live command-and-control infrastructure. The sources do not report a campaign-wide victim count, infection rate, or financial-loss figure, so the findings do not establish how widespread the activity was. Read Jamf Threat Labs’ technical report or Macworld’s incident coverage.
How does the fake installer use Gatekeeper?
- It presents a familiar-looking disk image. The mounted volume is named
Zoomand shows an app icon beside an Applications alias, resembling a typical Mac app installation layout. - It tells the user to override a security warning. The disk image background directs the user to System Settings, then Privacy & Security, to choose Open Anyway. Jamf says the app is ad-hoc signed, so macOS blocks an ordinary launch and the instructions encourage the user to override Gatekeeper.
- It asks for the local account password. The first-stage app, named
app_installer, displays a fake authorization prompt. In the samples Jamf analyzed, it checked the entered password against the Mac’s local account usingdscl; a “Downloading Zoom…” progress window helped make the process look genuine. - It conceals the password and launches another stage. The dropper stores the credential, base64-encoded and surrounded by random filler, in a decoy
data.jsonfile under~/.config/zoom/. Zero-width Unicode characters appended to a visible version value encode where the credential is located in the cache string. The dropper contains a second-stage universal Mach-O. Jamf’s analysis recorded an initial failed attempt to execute it through/dev/fd, followed by writing a temporary file and launching the payload withsudousing the validated password.
These are behaviors in Jamf’s analyzed samples, not a guarantee that every variant or infected Mac will behave identically. The key warning for users is the request to bypass a macOS security warning: stop and independently verify the app and its source rather than following installer-provided instructions.
#1 Best Overall
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
What can CloudSyncD do?
Jamf says the analyzed second stage supports both Apple silicon and Intel Macs. It gathers host and hardware information, checks in with command-and-control infrastructure, and can receive encrypted tasks containing Mach-O executables or gzipped tar archives. For the analyzed live implant, Jamf observed beacon intervals of 8 to 16 seconds; that is a sample-specific observation, not a universal timing guarantee.
Jamf’s report lists the live sample endpoints as orchid-led[.]com/macos/jquery[.]js and bjzhishang[.]com/macos/jquery[.]js. The defanged addresses are included here as indicators, not links to visit; Jamf says the path impersonates a jQuery resource.
Rank #2
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
What did researchers not observe?
In the analyzed session, Jamf did not observe the implant being moved to its configured install directory or a LaunchAgent or LaunchDaemon being created. That means the report does not establish that persistence was set up in that session; it is not evidence that persistence is impossible in another build or run.
Jamf also says it found no built-in functions in the analyzed malware for collecting browser credentials, Keychain contents, or cryptocurrency wallets. That limitation does not make the threat harmless: the installer phishes the local account password and uses it to launch a privileged second stage.
Rank #3
- ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
What should you do if you entered your Mac password?
If you entered your password into an installer that you now suspect was fake, contact your organization’s IT or security team, if applicable, or a qualified incident responder. Jamf’s report describes the analyzed malware, but it does not provide a consumer cleanup procedure that can be assumed to fit every possible infection. Avoid relying on improvised removal steps when the Mac may be compromised.
For future downloads, use the Mac App Store or the software developer’s official site, and inspect unexpected links before opening them. A setup guide asking you to override Gatekeeper is a strong reason to stop and verify the source independently. Gatekeeper is a security control, not a guarantee that every app it permits is safe. Macworld also advises avoiding downloads from unfamiliar repositories. See Macworld’s consumer guidance.
Rank #4
- ONGOING PROTECTION Download instantly & install protection for 10 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
How can IT check for CloudSyncD?
Jamf publishes SHA-256 hashes, command-and-control indicators, and file paths for the samples it analyzed. Reported artifacts include the original Zoom.dmg, app_installer, the development build’s ~/.config/zoom/data.json, and the implant path ~/.local/share/cloudsync/.config/logs/sync.err. These are useful investigation leads, not a complete signature set: Jamf notes that live builds and configurations differ. Analysts should consult the full IOC section in the primary report and treat hashes as sample-specific, dated indicators.
Jamf says organizations using its products can configure threat-prevention, advanced threat-control, and web-protection capabilities to block and report similar threats. This is guidance from the vendor that analyzed the samples, not an independent effectiveness test.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Best Value
- ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

