macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Summary

macOS users are being targeted by a fake Zoom installer that delivers a backdoor called CloudSyncD. The dropper embeds a Mach-O file within itself, which is extracted and executed at runtime.

IFF Assessment

FOE

The discovery of a new backdoor targeting macOS users represents a threat to individuals and organizations, as it allows for unauthorized access and potential data exfiltration.

Defender Context

Defenders should be aware of this new threat vector targeting macOS users through deceptive software installers. It highlights the continued importance of verifying software sources and implementing robust endpoint detection and response (EDR) solutions to identify and mitigate novel backdoors.

Read Full Story →