Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS.
Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It is initiated by the use of a disk image that is made to resemble the Zoom installer.
When a package is opened, it appears as a volume titled Zoom and uses familiar installation elements to create the impression that the application is genuine.
As part of the installation process, the fake installer displays a password prompt as part of the fake installer, which bypasses macOS Gatekeeper, permitting the ad-hoc signed application to run despite the operating system's security checks.
CloudSyncD checks the credentials entered against the local account before the malware continues. Instead of transmitting the password immediately, CloudSyncD stores it locally within a fake configuration file in lieu of transmitting it to a third party.
Through a normal inspection of the file, it may be difficult to identify the password because it is concealed using encoded data and invisible zero-width Unicode characters. The stolen password is then used as a means of executing the malware's second stage with elevated privileges.
Within the dropper, CloudSyncD is packaged as a universal Mach-O binary capable of being executed on Intel as well as Apple silicon Macs.
The malware attempts to execute the payload using an anonymous file descriptor as a first step, avoiding conventional file writing methods. It is possible to write the payload to disk temporarily and execute it by using sudo using the captured password, if that method fails as a result of macOS security protections.
Instead of stealing information conventionally, the second stage functions as a backdoor. It establishes communication with the attacker's infrastructure and receives additional executable files or compressed archived archives. CloudSyncD's second-stage implant is relatively quiet after it has been injected. It provides a way for the operator to deliver further malware or tools after the initial compromise.
By creating a working directory and maintaining encrypted activity logs, the malware avoids the need for a visible persistence mechanism. Check-ins occur every 8 to 16 seconds and include a hardware identifier, suggesting a periodic check-in is occurring. Compared to a simple command shell, the C2 channel provides the attackers with greater flexibility.
Using CloudSyncD, the compromised Mac can be supplied with compressed archives or executables, which can then be used to run the supplied content. Jamf Threat Labs identified multiple later builds of the backdoor communicating with two live domains following the initial infection. This enables the backdoor to serve as a delivery mechanism for additional malware or tools.
They use the same URI structure, which was designed to resemble a request for a jQuery script.
Both domains were registered with the same registrar in 2011 and were protected by Cloudflare. As of the time of the researchers’ analysis, neither domain was flagged by a security service. A number of technical similarities were also observed between the different samples, including similar string-obfuscation schemes, installation paths, daemon names, and process disguise schemes.
More importantly, the builds shared the same C2 encryption key and initialization vector, which means network traffic captured from different versions could potentially be decrypted using recovered configuration material. According to the findings, CloudSyncD had moved from an unfinished test build to a functional backdoor utilizing social engineering, while maintaining a relatively simple infection route.
Researchers distinguish the malware from a conventional infostealer despite the fact that it collects system and user information for reconnaissance. Rather than being sent to the attackers, the captured password is used locally to obtain elevated privileges, while the backdoor's primary function is to provide access and facilitate the execution of additional payloads.
Read the original article:
