CloudSyncD macOS backdoor with fake Zoom installer and live C2
Malware Activity
Summary
Hide ▲
Show ▼
The CloudSyncD macOS backdoor has advanced from development testing to samples configured against live C2 infrastructure, increasing the risk of real-world deployment. It arrives through a fake Zoom installer that pushes users to bypass Gatekeeper and enter a password. The implant uses encrypted C2, launches a second stage with elevated privileges, and can deliver additional payloads for remote execution. No confirmed infections were reported, but the activity shows operational readiness rather than a proof-of-concept.
Related Happenings
MacSync macOS infostealer with iCloud calendar payload delivery
Malware Activity
H score29
First: 24.09.2026 23:53
Last: 24.09.2026 23:53
Sources 1
About this happening:
MacSync now uses public iCloud calendar events to deliver fresh payloads on macOS, expanding its infection chain and increasing the risk of credential theft and re...
MacSync macOS infostealer with iCloud calendar payload delivery
Malware ActivityAbout this happening: MacSync now uses public iCloud calendar events to deliver fresh payloads on macOS, expanding its infection chain and increasing the risk of credential theft and re...
UAT-11795 Starland RAT trojanized installer malware activity
Malware Activity
H score31
First: 16.07.2026 13:19
Last: 16.07.2026 13:19
Sources 1
About this happening:
The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....
UAT-11795 Starland RAT trojanized installer malware activity
Malware ActivityAbout this happening: The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....
Zoom security patch release for CVE-2026-53412
Security Patch Release
H score43
First: 15.07.2026 23:16
Last: 15.07.2026 23:16
Sources 1
About this happening:
Zoom released Windows security patches covering CVE-2026-53412 and three additional flaws across Zoom Workplace, Windows VDI, Zoom Rooms, Contact Center, a...
Zoom security patch release for CVE-2026-53412
Security Patch ReleaseAbout this happening: Zoom released Windows security patches covering CVE-2026-53412 and three additional flaws across Zoom Workplace, Windows VDI, Zoom Rooms, Contact Center, a...
CrashStealer macOS information stealer activity
Malware Activity
H score10
First: 13.07.2026 20:36
Last: 13.07.2026 20:36
Sources 1
About this happening:
CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
CrashStealer macOS information stealer activity
Malware ActivityAbout this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
Easy-day-js malware delivery through poisoned Mastra packages
Malware Activity
H score29
First: 22.06.2026 14:30
Last: 22.06.2026 14:30
Sources 1
About this happening:
A poisoned Mastra package chain delivered malware through easy-day-js, creating compromise risk across Windows, MacOS and Linux systems. The payload disabled TLS...
Easy-day-js malware delivery through poisoned Mastra packages
Malware ActivityAbout this happening: A poisoned Mastra package chain delivered malware through easy-day-js, creating compromise risk across Windows, MacOS and Linux systems. The payload disabled TLS...
Timeline
-
01.10.2026 16:30 1 articles · 2h ago
CloudSyncD is first seen in a build under development
Initial DisclosureJamf Threat Labs first encountered CloudSyncD on September 15 in a build that was still under development, showing the macOS backdoor before it reached live command-and-control infrastructure.
Show sources
- CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer — www.infosecurity-magazine.com — 01.10.2026 16:30
-
01.10.2026 16:30 1 articles · 2h ago
CloudSyncD samples point to live C2 infrastructure
Campaign Scope UpdateTwo days after the first encounter, Jamf found CloudSyncD samples configured against live command-and-control (C2) infrastructure across more than one domain, indicating the operation had progressed toward deployment.
Show sources
- CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer — www.infosecurity-magazine.com — 01.10.2026 16:30
-
01.10.2026 16:30 2 articles · 2h ago
Jamf details a fake Zoom installer and password-harvesting second stage
Technical Analysis UpdateJamf's September 30 research says CloudSyncD arrives as a disk image designed to resemble a legitimate Zoom installer, pushes users to override macOS security protections through System Settings, validates a local password prompt, stores the password in a decoy configuration file with zero-width Unicode characters, and uses it to launch the second stage with elevated privileges; Jamf also said the implant did not show browser, Keychain, or cryptocurrency wallet theft, did not install persistence during analysis, and was found through VirusTotal monitoring with no confirmed infections.
Show sources
- CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer — www.infosecurity-magazine.com — 01.10.2026 16:30
- CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer — www.infosecurity-magazine.com — 01.10.2026 16:30