CloudSyncD: fake Zoom installer hides password in zero-width Unicode, drops macOS backdoor
Jamf Threat Labs detailed CloudSyncD, a two-stage macOS backdoor. A fake Zoom installer tricks victims into bypassing Gatekeeper and entering an admin password, which is concealed in a decoy JSON file via zero-width Unicode, then passed to sudo to run an embedded Mach-O implant with root privileges and C2 beaconing.
- Fake Zoom DMG requires bypassing Gatekeeper and entering an admin password
- Password is hidden in data.json via zero-width Unicode and passed to sudo
- Implant beacons host UUID, CPU, RAM, OS and username to C2 every 8–16 seconds
- C2 traffic goes to orchid-led[.]com and bjzhishang[.]com via /macos/jquery.js
Read next
Security