← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Fake Mac Zoom installer bypasses Gatekeeper to install infostealer, Jamf discovers

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Jamf discovered a fake Mac Zoom installer named CloudSyncD.
  • The malware bypasses Apple's Gatekeeper by instructing users to manually allow installation.
  • It installs Zoom but also an infostealer that captures data every eight seconds.
  • Users are advised to only install apps from official sources.

Malicious Installer Discovered

Cybersecurity company Jamf has uncovered a deceptive Mac installer for the videoconferencing application Zoom. This malicious software, identified as CloudSyncD, employs a method to circumvent Apple's Gatekeeper security feature, which is designed to prevent unauthorized applications from running on macOS.

Gatekeeper Bypass Mechanism

Typically, macOS blocks unnotarized applications. CloudSyncD, however, presents a disk image that mimics a standard installer but includes a background image with explicit instructions. These instructions guide users through the process of manually overriding Gatekeeper by navigating to System Settings, Privacy & Security, and selecting 'Open Anyway', followed by entering their administrator password. This social engineering tactic makes the bypass seem like a normal part of the installation process.

Infostealer Functionality

Upon successful installation, CloudSyncD not only installs the legitimate Zoom application but also deploys an infostealer. This malicious component is designed to capture user-entered data and transmit it to an attacker's server. The exfiltration of data can occur as frequently as every eight seconds, indicating a persistent and rapid data theft capability.

Security Implications and User Advice

The discovery of CloudSyncD highlights the ongoing threat of sophisticated malware targeting macOS users. The method of bypassing Gatekeeper by manipulating user interaction represents a notable security concern. Users are strongly advised to download and install applications exclusively from the official Mac App Store or directly from the websites of trusted developers to mitigate such risks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity firm Jamf identified a malicious Mac installer disguised as a Zoom application that bypasses Apple's Gatekeeper protection. The installer, dubbed CloudSyncD, installs both Zoom and an infostealer that exfiltrates user data, posing a significant threat to user privacy and security.