Cybersecurity company Jamf has uncovered a deceptive Mac installer for the videoconferencing application Zoom. This malicious software, identified as CloudSyncD, employs a method to circumvent Apple's Gatekeeper security feature, which is designed to prevent unauthorized applications from running on macOS.
Typically, macOS blocks unnotarized applications. CloudSyncD, however, presents a disk image that mimics a standard installer but includes a background image with explicit instructions. These instructions guide users through the process of manually overriding Gatekeeper by navigating to System Settings, Privacy & Security, and selecting 'Open Anyway', followed by entering their administrator password. This social engineering tactic makes the bypass seem like a normal part of the installation process.
Upon successful installation, CloudSyncD not only installs the legitimate Zoom application but also deploys an infostealer. This malicious component is designed to capture user-entered data and transmit it to an attacker's server. The exfiltration of data can occur as frequently as every eight seconds, indicating a persistent and rapid data theft capability.
The discovery of CloudSyncD highlights the ongoing threat of sophisticated malware targeting macOS users. The method of bypassing Gatekeeper by manipulating user interaction represents a notable security concern. Users are strongly advised to download and install applications exclusively from the official Mac App Store or directly from the websites of trusted developers to mitigate such risks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cybersecurity firm Jamf identified a malicious Mac installer disguised as a Zoom application that bypasses Apple's Gatekeeper protection. The installer, dubbed CloudSyncD, installs both Zoom and an infostealer that exfiltrates user data, posing a significant threat to user privacy and security.