New macOS malware masquerades as Zoom installer
Jamf Threat Labs reported new macOS malware that poses as a Zoom installer: it installs the real app but also silently drops an infostealer called CloudSyncD. The malware bypasses Gatekeeper by instructing users to override it, and can send stolen data to attackers as often as every 8 seconds.
- Malware ships as a disk image named Zoom with a standard app icon
- CloudSyncD captures user-entered data and reports every 8 seconds
- Users are told to manually override macOS Gatekeeper to run it
- The infostealer also enables remote command execution by attackers
Read next
Security