Find notable cyber news and cases, enriched with sources, timelines, and signals.

CloudSyncD macOS backdoor with fake Zoom installer and live C2

Malware Activity
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

The CloudSyncD macOS backdoor has advanced from development testing to samples configured against live C2 infrastructure, increasing the risk of real-world deployment. It arrives through a fake Zoom installer that pushes users to bypass Gatekeeper and enter a password. The implant uses encrypted C2, launches a second stage with elevated privileges, and can deliver additional payloads for remote execution. No confirmed infections were reported, but the activity shows operational readiness rather than a proof-of-concept.

Related Happenings

MacSync macOS infostealer with iCloud calendar payload delivery

Malware Activity
H score29 First: 24.09.2026 23:53 Last: 24.09.2026 23:53 Sources 1

About this happening: MacSync now uses public iCloud calendar events to deliver fresh payloads on macOS, expanding its infection chain and increasing the risk of credential theft and re...

UAT-11795 Starland RAT trojanized installer malware activity

Malware Activity
H score31 First: 16.07.2026 13:19 Last: 16.07.2026 13:19 Sources 1

About this happening: The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....

Zoom security patch release for CVE-2026-53412

Security Patch Release
H score43 First: 15.07.2026 23:16 Last: 15.07.2026 23:16 Sources 1

About this happening: Zoom released Windows security patches covering CVE-2026-53412 and three additional flaws across Zoom Workplace, Windows VDI, Zoom Rooms, Contact Center, a...

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

Easy-day-js malware delivery through poisoned Mastra packages

Malware Activity
H score29 First: 22.06.2026 14:30 Last: 22.06.2026 14:30 Sources 1

About this happening: A poisoned Mastra package chain delivered malware through easy-day-js, creating compromise risk across Windows, MacOS and Linux systems. The payload disabled TLS...

Timeline

  1. 01.10.2026 16:30 1 articles · 2h ago

    CloudSyncD is first seen in a build under development

    Initial Disclosure

    Jamf Threat Labs first encountered CloudSyncD on September 15 in a build that was still under development, showing the macOS backdoor before it reached live command-and-control infrastructure.

    Show sources
  2. 01.10.2026 16:30 1 articles · 2h ago

    CloudSyncD samples point to live C2 infrastructure

    Campaign Scope Update

    Two days after the first encounter, Jamf found CloudSyncD samples configured against live command-and-control (C2) infrastructure across more than one domain, indicating the operation had progressed toward deployment.

    Show sources
  3. 01.10.2026 16:30 2 articles · 2h ago

    Jamf details a fake Zoom installer and password-harvesting second stage

    Technical Analysis Update

    Jamf's September 30 research says CloudSyncD arrives as a disk image designed to resemble a legitimate Zoom installer, pushes users to override macOS security protections through System Settings, validates a local password prompt, stores the password in a decoy configuration file with zero-width Unicode characters, and uses it to launch the second stage with elevated privileges; Jamf also said the implant did not show browser, Keychain, or cryptocurrency wallet theft, did not install persistence during analysis, and was found through VirusTotal monitoring with no confirmed infections.

    Show sources