Security researchers have identified a new malware targeting macOS users through a deceptive Zoom installer. This emerging threat, known as CloudSyncD, represents a sophisticated backdoor designed to maintain persistent, stealthy access to compromised systems.
Discovery and Evolution of CloudSyncD
CloudSyncD was first detected by researchers at Jamf in mid-September as it was still under development. Within a short period, additional samples surfaced, indicating a transition from testing phases to active deployment.
The malware spreads through common social engineering tactics that trick users into downloading a malicious Zoom installer. Once executed, this dropper mounts a disk image named Zoom, deceiving users into believing they are installing the legitimate conferencing software, while in reality, they are activating CloudSyncD.
Technical Details and Execution Process
The dropper contains a universal Mach-O file of approximately 756 KB, which it extracts and attempts to execute. The execution often fails due to macOS System Integrity Protection, prompting the dropper to write the payload temporarily to disk and execute it using elevated privileges obtained through the victim’s password.
Once activated, CloudSyncD’s configuration is encrypted within its binary and decrypted during runtime. It operates through a daemon named CloudSyncD, performing reconnaissance and exfiltrating data to its command and control (C2) server.
Current Deployment and Indicators of Compromise
Recent observations show multiple builds of CloudSyncD across two domains, masquerading as jQuery scripts to evade detection. These domains, registered in 2011, utilize Cloudflare for protection and were undetected at the time of reporting.
CloudSyncD’s builds share common features such as obfuscation tables, installation paths, and C2 communication protocols. These elements allow researchers to decrypt traffic using data from any build, providing consistent indicators of compromise (IOCs) across deployments.
Implications and Security Recommendations
The advent of CloudSyncD highlights the ongoing evolution of macOS-targeted malware. This threat underscores the importance of vigilance against social engineering attacks that exploit user trust to gain unauthorized access.
Users and organizations are advised to remain cautious of unexpected software installation prompts and to verify the authenticity of installers. Employing robust security measures and monitoring the provided IOCs can help mitigate the risks posed by such sophisticated threats.
