Insights

That "Zoom Installer" Might Not Be Zoom

Cybercriminals have a new trick, and it targets Mac users. Security researchers recently uncovered a piece of malware called CloudSyncD — and it gets onto your…

Cybercriminals have a new trick, and it targets Mac users. Security researchers recently uncovered a piece of malware called CloudSyncD — and it gets onto your computer disguised as a Zoom installer.

Here's what's happening, why it matters, and what you can do to stay safe.

What Is This Threat?

Researchers at Jamf Threat Labs (a well-known Mac security firm) discovered a new malicious program hiding inside a fake Zoom download. When an unsuspecting user runs it, they think they're installing Zoom — but they're actually handing attackers a secret back door into their Mac.

This kind of attack has a name: a backdoor. Unlike ransomware or viruses that make their presence known, a backdoor sits quietly on your computer, waiting. The attacker can return at any time — days, weeks, even months later — to access your files, spy on your activity, or push further attacks.

How Does Someone Get Infected?

The attack typically starts with a convincing message — an email, a LinkedIn message, or even a calendar invite — asking you to join a video call and install or update Zoom to do so.

When you run the fake installer, here's what happens behind the scenes:

  1. It tricks you into bypassing your own security. The fake installer displays instructions telling you to click "Open Anyway" in your Mac's security settings. This step overrides a built-in Mac safety feature called Gatekeeper, which is specifically designed to block untrusted software.
  1. It asks for your Mac password. It shows a normal-looking password prompt. But instead of using that password to install Zoom, it secretly stores it in a hidden file on your computer — disguised to look like a routine Zoom configuration file.
  1. While you watch a fake "installing Zoom" progress bar, everything above is happening in the background.
  1. A hidden program quietly activates. Every 8 to 16 seconds, it "phones home" to the attacker's server, checking for instructions. The attacker can then send commands directly to your computer — including running additional malicious programs.

Why Is This Particularly Sneaky?

A few things make CloudSyncD harder to detect than typical malware:

  • It doesn't steal your data — at least not right away. Most malware immediately grabs passwords, credit card numbers, or browser history. CloudSyncD doesn't. It just waits, quietly, for further instructions. That means your security software may not flag it as a threat.
  • It hides your password in plain sight. Your password is stored in a file that looks completely normal. It uses a clever trick with invisible characters (characters you can't see but a computer can read) to hide exactly where in the file your password is buried.
  • It leaves very little evidence. Many malicious programs add themselves to your Mac's startup list so they run every time you turn on your computer. CloudSyncD doesn't — making it harder to notice something is wrong.

Who Is Doing This?

Security researchers haven't pinned this attack to a specific group yet, but they note that fake Zoom installers have been a favourite tool of state-sponsored hackers — including groups linked to North Korea and Iran — often used in fake job interview or business meeting scams.

Whether this is the work of a nation-state or a criminal group, the goal is the same: get a quiet foothold on your computer before you realize anything is wrong.

What Should You Do?

You don't need to be a tech expert to protect yourself. A few straightforward habits go a long way:

  1. Only download Zoom (and any software) from the official website. Go directly to zoom.us — not a link someone sent you. If a link in an email or message is asking you to install or update software, treat it with suspicion.
  2. Never click "Open Anyway" unless you know exactly what you're installing. Your Mac's Gatekeeper protection exists for a reason. If a program is asking you to bypass it, that's a red flag.
  3. Be cautious with unexpected meeting invites or job opportunities. These attacks often arrive dressed as a recruiter reaching out, a client inviting you to a call, or a colleague asking you to "update Zoom before the meeting." When in doubt, verify through a separate channel before clicking anything.
  4. Make sure your Mac is kept up to date. Apple regularly releases security updates. Staying current means attackers have fewer known vulnerabilities to exploit.
  5. Consider a managed security solution. Consumer antivirus can catch the obvious stuff, but threats like CloudSyncD are designed to fly under the radar. A managed security service actively monitors for unusual activity on your devices — including the kind of quiet, persistent behaviour this backdoor uses.

What About Windows Users?

CloudSyncD specifically targets Macs — but that doesn't mean Windows users are off the hook. The same social engineering tactics behind this attack (fake installers, meeting invite scams, "please update Zoom" messages) are used constantly against Windows machines too. In fact, Windows has historically been the more common target simply because more businesses run it.

If your team uses Windows, the same rules apply: only download software from official sources, be suspicious of any prompt asking you to bypass security warnings, and make sure your devices are protected by more than just built-in defenses. The method of attack may differ, but the playbook is the same.

The Bigger Picture

Attacks like CloudSyncD are a reminder that cybercriminals aren't always after a quick smash-and-grab. Sometimes they play a longer game — getting in quietly, learning your environment, and striking when the time is right.

For businesses in regulated industries — healthcare, financial services, insurance, accounting — a quiet attacker with access to your systems isn't just an IT problem. It's a compliance problem, a liability problem, and potentially a client trust problem.

If you're unsure whether your business is protected against this kind of threat, we're happy to take a look. Book a free 30-minute consultation — no pressure, no jargon, just honest answers.