Monitoring time before live-server builds appeared: 2 days (Source: Jamf Threat Labs (September 30, 2026))
The password is a key, not the loot
When malware asks for a password, most people assume it wants to steal it. CloudSyncD does something different with it. Jamf Threat Labs found that the password is not recorded or sent anywhere. The malware checks it, hides it locally and uses it to launch a second program with administrator rights.
This is an old trick used in a way that a common watch-list would not cover. The password is the key to stage two, not the loot. A team that monitors only for stolen credentials leaving the machine would have nothing to see, because the password itself never leaves the machine.
What Jamf found
Jamf's researchers spotted the dropper while routinely monitoring executables in VirusTotal. The first sample, from September 15, 2026, was an unfinished test build. After two more days of watching, they found related samples wired to working command servers on more than one domain. Jamf reads this as a move from testing toward deployment.
Infosecurity Magazine reports that Jamf did not report any confirmed infections. Jamf also did not observe the malware setting up persistence, and no task was delivered to the implant during its analysis.
How the lure works
Victims receive a disk image. Opening it shows a drive labeled Zoom, laid out like a normal Mac installer. Instructions in the window's artwork walk the victim through approving the blocked app by hand, ending with the administrator password.
Those steps override Gatekeeper, the macOS check that blocks software it cannot verify. The app is only ad-hoc signed, so macOS refuses a normal double-click. The artwork teaches the user how to overrule that refusal.
The installer then shows a fake authorization prompt. It checks each password against the local account with a macOS command called dscl and repeats the prompt until the check succeeds. A fake window reading "Downloading Zoom..." follows, with no download behind it.
Hiding the password in plain sight
The dropper saves the password in a file at ~/.config/zoom/data.json. A glance suggests routine app preferences: a display theme, a language and a notifications setting. The password is encoded and buried inside a long value, with 32 to 64 random characters of filler on each side.
Nothing visible marks where the real value starts. That detail sits in the neighbouring version field, after the visible "1.0.0". There, 48 invisible Unicode characters encode the position and length of the password. The filler differs on every run, so the position changes each time.
The second stage
The dropper carries its payload inside itself. It is a universal Mach-O, a Mac program format that runs on both Apple silicon and Intel. It was roughly 756 KB in the development build.
The dropper first tries to run it through /dev/fd, presumably so the file never touches disk. This failed in Jamf's testing. Jamf says it will fail on most macOS systems because of System Integrity Protection. The fallback writes a temporary file and runs it with sudo and the harvested password.
The implant then beacons to its server every 8 to 16 seconds. It sends a survey of just under 2 KB covering hardware, operating system and user name. After that, each check-in carries only the hardware ID. The server can reply with an executable or a compressed archive to run. Jamf notes that this tasking delivers programs, not shell commands, so defenders should look for a newly written or fileless Mach-O.
What Jamf did not see
The research has limits. Jamf's builds had an empty download URL, so a planned application swap never ran in any test. The implant was never seen installing itself as cloudsyncd. Jamf could not say which bundle the swap would have placed.
Both live domains were registered in 2011, sit behind Cloudflare and had no detections at the time of writing. Every build shares the same encryption key. Beacon traffic from any build can therefore be decrypted with material recovered from another.
Questions for your Mac and security teams
First, can employees run sudo on their own Macs? The attack depends on a password that carries administrator rights. Second, does your endpoint tooling flag a newly written or fileless Mach-O? Jamf names that as the observable.
Third, can your team hunt for known traces? Jamf lists ~/.config/zoom/data.json and ~/.local/share/cloudsync/.config/logs/sync.err. The first line of a recovered log names both the server and the host.
Fourth, do staff know that an installer telling you to click Open Anyway is itself a warning sign? Software that explains how to switch off a safety check is asking for trust it has not earned.
Jamf describes the password prompt as the oldest technique available. The malware's main tool here is a polite request, and the person who answers it holds the key.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Jamf Threat Labs.





