CloudSyncD MacOS Backdoor Used Fake Zoom Installer to Steal Passwords


Cybersecurity researchers have identified a new macOS backdoor called CloudSyncD that uses a fake Zoom installer to trick users into providing their computer passwords. The malware was discovered by Jamf Threat Labs and uses a two-stage infection process to gain elevated access and communicate with attacker-controlled servers.

One of the most unusual features of the malware is its use of zero-width Unicode characters to hide information about a stolen password inside what appears to be a normal configuration file.

Technical Details

CloudSyncD is distributed through a malicious disk image designed to look like a legitimate Zoom installer. The installer includes instructions telling users to bypass macOS Gatekeeper by going to System Settings and manually allowing the application to run.

Once the fake installer is launched, the first-stage program, called app_installer, displays a fake authorization window asking for the user’s administrator password. It checks the entered password locally using macOS’s dscl command. If the password is incorrect, the malware can continue prompting the victim.

The stolen password is not immediately sent to the attackers. Instead, the malware stores it inside a file called data.json. The password is Base64-encoded and placed inside a larger string containing random characters.

The malware then uses U+200B ZERO WIDTH SPACE and U+200C ZERO WIDTH NON-JOINER characters. These characters are invisible during normal viewing and encode the location and length of the hidden password. This technique allows malicious information to be concealed without obviously changing the appearance of the file. 

The second stage is an embedded Mach-O executable capable of running on both Intel-based and Apple Silicon Macs. The malware attempts to execute the payload without initially writing it to disk. When that approach fails because of macOS security protections, it can create a temporary file and use the captured password with sudo to execute the backdoor with elevated privileges.

Impact

After execution, CloudSyncD collects information about the infected Mac, including hardware and operating-system details, account information and network-related data. It communicates with a command-and-control server and can periodically check for additional instructions.

Researchers observed check-ins occurring approximately every 8 to 16 seconds in analyzed samples. The backdoor can receive executable files or compressed archives, potentially allowing attackers to deploy additional malware on an infected system. 

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: