CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS

Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS. 

Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It is initiated by the use of a disk image that is made to resemble the Zoom installer.
When a package is opened, it appears as a volume titled Zoom and uses familiar installation elements to create the impression that the application is genuine. 
Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS.
Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It is initiated by the use of a disk image that is made to resemble the Zoom installer. When a package is opened, it appears as a volume titled Zoom and uses familiar installation elements to create the impression that the application is genuine.
During installation, victims are presented with an authorization prompt designed to obtain their account password. The installer also relies on the user allowing the application to run despite macOS Gatekeeper protections. Before continuing with the infection process, CloudSyncD verifies the supplied credentials against the local account. Rather than immediately forwarding those credentials to its operators, the malware retains them on the compromised machine inside a disguised configuration file.
The stored password is deliberately made difficult to identify through an ordinary inspection of the file. CloudSyncD combines encoded information with invisible zero-width Unicode characters, effectively concealing the credential within otherwise inconspicuous data. The password subsequently becomes useful to the malware itself, allowing the next stage of the infection to run with greater privileges. The accompanying CloudSyncD component is delivered as a universal Mach-O binary, allowing it to operate across both Intel and Apple silicon systems.
For the next stage, the malware first tries to launch its payload without relying on a conventional file being written to the system. If macOS protections prevent this approach, CloudSyncD can fall back to placing the payload temporarily on disk. It can then make use of the previously obtained password with `sudo` to execute the component with elevated permissions.
Once running, the second-stage component operates primarily as a backdoor rather than as a conventional information-stealing program. Its purpose is to establish contact with attacker-controlled infrastructure and create a channel through which additional executables or compressed archives can be delivered. This gives the operators an opportunity to introduce further malware or tooling after access to the Mac has already been established.
By creating a working directory and maintaining encrypted activity logs, the malware avoids the need for a visible persistence mechanism. Check-ins occur every 8 to 16 seconds and include a hardware identifier, suggesting a periodic check-in is occurring. Compared to a simple command shell, the C2 channel provides the attackers with greater flexibility.
Using CloudSyncD, the compromised Mac can be supplied with compressed archives or executables, which can then be used to run the supplied content. Jamf Threat Labs identified multiple later builds of the backdoor communicating with two live domains following the initial infection. This enables the backdoor to serve as a delivery mechanism for additional malware or tools. They use the same URI structure, which was designed to resemble a request for a jQuery script.
Both domains were registered with the same registrar in 2011 and were protected by Cloudflare. As of the time of the researchers’ analysis, neither domain was flagged by a security service. A number of technical similarities were also observed between the different samples, including similar string-obfuscation schemes, installation paths, daemon names, and process disguise schemes.
More importantly, the builds shared the same C2 encryption key and initialization vector, which means network traffic captured from different versions could potentially be decrypted using recovered configuration material. According to the findings, CloudSyncD had moved from an unfinished test build to a functional backdoor utilizing social engineering, while maintaining a relatively simple infection route.
Researchers distinguish the malware from a conventional infostealer despite the fact that it collects system and user information for reconnaissance. Rather than being sent to the attackers, the captured password is used locally to obtain elevated privileges, while the backdoor's primary function is to provide access and facilitate the execution of additional payloads.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: