Computers

Fake Zoom Installer Bypasses Gatekeeper, Steals Mac Data

Jamf found a fake Zoom installer for Mac, dubbed CloudSyncD, that bypasses Apple's Gatekeeper and installs an infostealer.

Security researchers at Jamf have discovered a fake Zoom installer for Mac that bypasses Apple's Gatekeeper protection and installs an infostealer. The malware, dubbed CloudSyncD, arrives as a disk image that mounts as a volume named Zoom, according to 9to5mac.com.

Once mounted, the installer's background image instructs users to bypass Gatekeeper via System Settings. This social engineering step allows the malicious software to run despite Apple's built-in security checks.

After installation, the malware installs a legitimate copy of Zoom alongside an infostealer that captures user-entered data and sends it to the attacker's server. The stolen data can be transmitted as frequently as every eight seconds.

Jamf's discovery highlights the continued risk of fake installers that trick users into weakening macOS security. Users are advised to download software only from official sources and to be wary of any installer that asks them to disable Gatekeeper.

Quick answers

What is CloudSyncD?

CloudSyncD is the name given by Jamf to a fake Zoom installer for Mac that bypasses Apple's Gatekeeper and installs an infostealer.

How does the fake Zoom installer bypass Gatekeeper?

The installer's background image instructs users to bypass Gatekeeper via System Settings, allowing the malware to run.

What does the infostealer do?

It captures user-entered data and sends it to the attacker's server as frequently as every eight seconds.

Source