Skip to content
New macOS Malware CloudSyncD Disguised as Zoom Installer

New macOS Malware CloudSyncD Disguised as Zoom Installer

First seen 1 Oct 2026, 00:00 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 00:01 UTC
  • •CloudSyncD disguises itself as a Zoom installer to trick users.
  • •It captures administrator passwords to enable remote command execution.
  • •The malware targets both Apple Silicon and Intel Macs.

CloudSyncD is a newly identified macOS malware that masquerades as a legitimate Zoom installer. Discovered by Jamf Threat Labs, it operates as a backdoor, capturing the user's administrator password and allowing remote command execution. The malware is delivered via a disk image named 'Zoom' that prompts users to bypass macOS's Gatekeeper security. Once installed, it can send data to attackers and execute additional malicious commands. The malware does not collect browser data or access keychain items, focusing instead on maintaining a low profile until further access is needed. It affects both Apple Silicon and Intel Macs. The attack vector relies on social engineering to trick users into providing their passwords. Current reports indicate that the malware is actively being deployed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-15
CloudSyncD identified in early development
Jamf Threat Labs discovered the malware in a testing phase, indicating initial development efforts.
iphoneaddict.fr
2026-09-17
Deployment phase confirmed
Researchers identified samples of CloudSyncD configured for active deployment, indicating a shift from testing to real-world attacks.
iphoneaddict.fr
2026-09-30
Public reports released
Multiple outlets, including Macworld and Apple World Today, published reports detailing the malware's functionality and attack vector.
Macworld

More articles in this cluster (4)

Following this threat?

Track CloudSyncD in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How does CloudSyncD operate?
CloudSyncD operates by masquerading as a Zoom installer and captures the user's administrator password to enable further malicious actions.
What systems are affected by CloudSyncD?
CloudSyncD affects macOS systems, specifically targeting both Apple Silicon and Intel architectures.
What should users do to protect themselves?
Users should avoid downloading software from untrusted sources and ensure they only install applications from the Mac App Store or verified developers.