Back to Intelligence

CloudSyncD: Fake Zoom macOS Installer Hides Stolen Passwords in Zero-Width Unicode — Detection and Removal Guide

SA
Security Arsenal Team
October 4, 2026
13 min read

Jamf Threat Labs has disclosed a new macOS backdoor dubbed CloudSyncD, delivered through a trojanized Zoom installer. The campaign is notable for an evasion technique we don't often see operationalized at this level: stolen user credentials are concealed using invisible zero-width Unicode characters, making the phished password effectively invisible in casual log review, plist inspection, and string dumps. Jamf first spotted the sample during routine VirusTotal hunting on September 15, assessed it as still under active development, and watched it evolve into a functional build within roughly 48 hours.

Why this matters to defenders: Zoom-themed lures remain one of the highest-conversion social engineering vectors against macOS fleets in hybrid-work environments. A backdoor that combines a trusted-brand installer, a native credential phishing dialog, and steganographic-style credential obfuscation is purpose-built to defeat both users and basic endpoint telemetry review. If your organization manages Macs — executive laptops, developer workstations, creative teams — you should treat this as an active, evolving threat and hunt today, not after the next revision ships.

This post breaks down the CloudSyncD attack chain, explains the zero-width Unicode concealment technique, and provides production-ready Sigma, KQL, and Velociraptor detection content plus a macOS triage and removal script.

Technical Analysis

Delivery and Masquerade

CloudSyncD arrives as a fake Zoom client installer. The lure mirrors the long-running pattern we've seen across macOS malware families (Atomic Stealer, Cthulhu, Realst, and multiple fake-Meeting/Teams campaigns): the victim is directed — typically via malvertising, SEO poisoning, or a fake meeting invite — to download what appears to be zoom.us software. The malicious installer is not distributed through Zoom's legitimate channels and would not carry a valid Zoom Video Communications Developer ID signature or notarization ticket.

Key behavioral indicators from Jamf's analysis:

  • Disguised application bundle mimicking the Zoom client, hosted outside the official zoom.us distribution infrastructure.
  • A payload component internally named CloudSyncD — the naming convention itself is a social-engineering layer, designed to blend into the noise of legitimate com.apple.* and cloud-sync daemons in launchctl output and LaunchAgent directories.
  • Rapid development cadence: Jamf observed the malware transition from an under-construction build to functional within approximately two days (September 15 → September 17). Expect continued iteration; static indicators from this initial disclosure will have a short shelf life.

The Credential Phish and Zero-Width Unicode Concealment

The centerpiece of this campaign is its handling of stolen credentials. The malware presents a fake system-style password prompt — the classic macOS technique of invoking osascript to render a native-looking dialog (e.g., "System Preferences wants to make changes" / "Zoom needs your password to install updates") with a hidden-answer text field. Once the user enters their password, CloudSyncD stores and/or transmits it obfuscated with zero-width Unicode characters.

Zero-width characters — code points such as U+200B (Zero Width Space), U+200C (Zero Width Non-Joiner), U+200D (Zero Width Joiner), and U+FEFF (Zero Width No-Break Space / BOM) — render as nothing on screen. Their UTF-8 byte sequences (e.g., E2 80 8B for U+200B) are fully present in the data but invisible in:

  • Terminal output and log viewers
  • defaults read and plist dumps
  • strings output reviewed by analysts
  • Many SIEM console renderings

From the attacker's perspective this buys several things: (1) the credential store is not trivially greppable by a responder searching for known passwords or password-adjacent strings; (2) zero-width sequences can double as a covert encoding channel — binary data can be mapped onto combinations of zero-width code points, an established steganographic trick previously seen in watering-hole JavaScript and now operationalized for credential handling on macOS; and (3) copy-paste of the obfuscated blob preserves the data, so the operator can recover the plaintext downstream.

MITRE ATT&CK mapping for the observed chain:

  • T1036.005 — Masquerading: Match Legitimate Name or Location (fake Zoom bundle; cloud-sync-style daemon name)
  • T1204.002 — User Execution: Malicious File (victim runs the trojanized installer)
  • T1056.002 — Input Capture: GUI Input Capture (fake credential dialog via AppleScript)
  • T1027.010 — Obfuscation: Command Obfuscation / steganographic concealment (zero-width Unicode encoding of stolen data)
  • T1543.001 / T1543.004 — Create or Modify System Process: Launch Agent / Launch Daemon (persistence typical of this malware class; CloudSyncD's naming strongly suggests LaunchAgent-based persistence)
  • T1041 — Exfiltration Over C2 Channel

Exploitation Status

This is not a vulnerability — there is no CVE involved. CloudSyncD is pure social engineering plus living-off-the-land abuse of legitimate macOS facilities (AppleScript dialogs, LaunchAgents). It is confirmed in-the-wild, still under active development as of Jamf's disclosure, and distributed through impersonated Zoom download lures. Because it requires no exploit, patching will not help; your control points are application control, user behavior, persistence monitoring, and egress filtering.

Detection & Response

The detections below focus on the durable behaviors: native credential phishing dialogs, persistence in LaunchAgents, execution from non-standard paths masquerading as Zoom, and zero-width Unicode artifacts in on-disk data. Note that a signature-matching detection on the string CloudSyncD alone is a short-lived control — the behavioral rules are the ones that survive the attacker's next build.

Sigma Rules

YAML
---
title: macOS Fake System Credential Prompt via AppleScript
id: 3f9c1a72-6b4e-4d1a-9f2c-8e7a5b3d01c4
status: experimental
description: Detects osascript execution displaying a hidden-answer dialog, a technique used by macOS malware such as CloudSyncD and Atomic Stealer to phish user credentials via fake system prompts.
references:
  - https://securityaffairs.com/200293/malware/fake-zoom-installer-hides-macos-backdoor-cloudsyncd.html
  - https://attack.mitre.org/techniques/T1056/002/
author: Security Arsenal
date: 2026/01/09
tags:
  - attack.credential_access
  - attack.t1056.002
logsource:
  category: process_creation
  product: macos
detection:
  selection_img:
    Image|endswith: '/osascript'
  selection_cli:
    CommandLine|contains:
      - 'with hidden answer'
      - 'display dialog'
  filter_apps:
    CommandLine|contains:
      - '/Applications/'
      - 'Jamf'
      - 'MDM'
  condition: selection_img and selection_cli and not filter_apps
falsepositives:
  - Legitimate internal IT provisioning scripts using AppleScript dialogs (constrain via MDM/Jamf process ancestry)
  - Managed installer frameworks that prompt for elevation
level: high
---
title: Suspicious LaunchAgent Persistence Mimicking Cloud Sync Service
id: 8d2e4b61-1a7f-4c93-b5e8-2f6d9a0c4e17
status: experimental
description: Detects creation of LaunchAgent or LaunchDaemon property lists with cloud-sync-themed names (as used by CloudSyncD) or written by non-package processes, indicating macOS persistence installation.
references:
  - https://securityaffairs.com/200293/malware/fake-zoom-installer-hides-macos-backdoor-cloudsyncd.html
  - https://attack.mitre.org/techniques/T1543/001/
author: Security Arsenal
date: 2026/01/09
tags:
  - attack.persistence
  - attack.t1543.001
  - attack.t1543.004
logsource:
  category: file_event
  product: macos
detection:
  selection_path:
    TargetFilename|contains:
      - '/Library/LaunchAgents/'
      - '/Library/LaunchDaemons/'
  selection_ext:
    TargetFilename|endswith: '.plist'
  selection_name:
    TargetFilename|contains:
      - 'cloudsync'
      - 'CloudSync'
      - 'syncd'
      - 'cloudd'
  filter_legit:
    TargetFilename|contains:
      - 'com.apple.'
      - 'com.google.Keystone'
      - 'com.microsoft.'
  condition: selection_path and selection_ext and selection_name and not filter_legit
falsepositives:
  - Legitimate third-party cloud storage agents (Dropbox, Box, OneDrive installers) — verify signer and install source
level: high
---
title: Application Execution Masquerading as Zoom from Non-Standard Path
id: 6c1b8f44-92de-4a06-bc53-7e0d1f9a2b85
status: experimental
description: Detects execution of binaries named as or impersonating the Zoom client from paths outside the legitimate /Applications/zoom.us.app bundle, consistent with trojanized installer delivery seen with CloudSyncD.
references:
  - https://securityaffairs.com/200293/malware/fake-zoom-installer-hides-macos-backdoor-cloudsyncd.html
  - https://attack.mitre.org/techniques/T1036/005/
author: Security Arsenal
date: 2026/01/09
tags:
  - attack.defense_evasion
  - attack.t1036.005
  - attack.execution
logsource:
  category: process_creation
  product: macos
detection:
  selection_name:
    Image|contains:
      - 'zoom'
      - 'Zoom'
  selection_paths:
    Image|contains:
      - '/tmp/'
      - '/var/folders/'
      - '/private/tmp/'
      - '/Users/Shared/'
      - '/Library/Application Support/'
      - '/Downloads/'
  filter_legit:
    Image|startswith: '/Applications/zoom.us.app/'
  condition: selection_name and selection_paths and not filter_legit
falsepositives:
  - Zoom auto-updater staging activity (rare; verify code signature on the executing binary)
level: high

The first rule is the highest-value behavioral detection in this set. osascript invoked with display dialog ... with hidden answer from a process that isn't your MDM or a known software installer is almost never benign in a managed fleet. The zero-width Unicode concealment itself is best hunted at the file-artifact layer — covered in the Velociraptor section below, since SIEM-side regex over raw byte sequences for U+200B-class code points is inconsistent across pipelines and tends to produce either silence or noise depending on how your collector normalizes UTF-8.

Microsoft Sentinel / Defender KQL

Defender for Endpoint on macOS surfaces process and file events into DeviceProcessEvents and DeviceFileEvents, so these hunts work directly against onboarded Mac fleets:

KQL — Microsoft Sentinel / Defender
// CloudSyncD hunt: credential phishing dialogs, fake Zoom execution, and suspicious LaunchAgent persistence on macOS
let lookback = 30d;
// 1) AppleScript hidden-answer password prompts (fake credential dialogs)
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where FileName =~ "osascript"
| where ProcessCommandLine has_any ("with hidden answer", "display dialog")
    and ProcessCommandLine has_any ("password", "Password", "System Preferences", "Zoom", "update")
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
;
// 2) Zoom-impersonating execution from non-standard locations
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where FileName has "zoom" or ProcessCommandLine has "zoom"
| where FolderPath !startswith "/Applications/zoom.us.app"
    and FolderPath has_any ("/tmp", "/var/folders", "/Users/Shared", "/Downloads", "/Library/Application Support")
| project TimeGenerated, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, SHA256
;
// 3) LaunchAgent/LaunchDaemon plist creation with cloud-sync-themed names
DeviceFileEvents
| where TimeGenerated > ago(lookback)
| where ActionType == "FileCreated"
| where FolderPath has_any ("LaunchAgents", "LaunchDaemons")
| where FileName has_any ("cloudsync", "syncd", "cloudd", "zoom")
    and FileName !has_any ("com.apple.", "com.google.Keystone", "com.microsoft.")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FolderPath, FileName, SHA256

Run each branch separately during triage; the union is useful for broad hunting but the per-branch pivots (especially process ancestry on the osascript hits) are where you'll separate CloudSyncD-class activity from legitimate admin scripting.

Velociraptor VQL

This hunt hunts two artifacts at once: persistence plists containing zero-width Unicode bytes (the CloudSyncD concealment technique) and live processes running from staging paths. The byte-level regex targets the UTF-8 encodings of U+200B, U+200C, U+200D, and U+FEFF inside LaunchAgent/LaunchDaemon plists — legitimate Apple and mainstream third-party plists essentially never contain these sequences, so hits here deserve immediate attention.

VQL — Velociraptor
-- CloudSyncD hunt: zero-width Unicode in persistence plists and masqueraded processes
LET plists = SELECT FullPath, Mtime, Data
FROM glob(globs=['/Library/LaunchAgents/*.plist', '/Library/LaunchDaemons/*.plist', '/Users/*/Library/LaunchAgents/*.plist'],
          accessor='file')
LET zw_hits = SELECT FullPath, Mtime,
    read_file(filename=FullPath, length=200000, accessor='file') AS Raw
FROM plists
WHERE Raw =~ '\\xE2\\x80[\\x8B\\x8C\\x8D]|\\xEF\\xBB\\xBF'
SELECT FullPath, Mtime, 'ZeroWidthUnicodeInPlist' AS Finding FROM zw_hits
UNION ALL
SELECT Exe AS FullPath, CreateTime AS Mtime,
       'SuspiciousProcess: ' + Name + ' | ' + CommandLine AS Finding
FROM pslist()
WHERE (Exe =~ '/tmp/|/var/folders/|/Users/Shared/|/Downloads/'
       OR Name =~ '(?i)cloudsync|syncd|zoom')
  AND Exe !~ '(?i)/Applications/zoom.us.app|/System/Library/|com.apple'

Triage and Removal Script (macOS)

Deploy via your MDM as an emergency script or run interactively during IR. It enumerates persistence, scans plists for zero-width Unicode byte sequences, identifies CloudSyncD artifacts, and quarantines (rather than deletes) suspicious items so forensic evidence is preserved.

Bash / Shell
#!/bin/bash
# CloudSyncD macOS triage and containment script — Security Arsenal IR
# Run as root. Quarantines suspicious artifacts to /var/quarantine_cloudsyncd for forensic preservation.

QUAR="/var/quarantine_cloudsyncd/$(date +%Y%m%d_%H%M%S)"
mkdir -p "$QUAR"
LOG="$QUAR/triage.log"
echo "[+] CloudSyncD triage started $(date)" | tee -a "$LOG"

# 1) Snapshot persistence locations
echo "[+] Enumerating LaunchAgents / LaunchDaemons" | tee -a "$LOG"
for d in /Library/LaunchAgents /Library/LaunchDaemons /Users/*/Library/LaunchAgents; do
  ls -la "$d" 2>/dev/null | tee -a "$LOG"
done

# 2) Scan plists for zero-width Unicode bytes (U+200B/C/D, U+FEFF)
echo "[+] Scanning plists for zero-width Unicode byte sequences" | tee -a "$LOG"
for d in /Library/LaunchAgents /Library/LaunchDaemons /Users/*/Library/LaunchAgents; do
  for f in "$d"/*.plist; do
    [ -f "$f" ] || continue
    if LC_ALL=C grep -qP '\xE2\x80[\x8B\x8C\x8D]|\xEF\xBB\xBF' "$f" 2>/dev/null; then
      echo "[!] ZERO-WIDTH UNICODE FOUND: $f" | tee -a "$LOG"
      cp -p "$f" "$QUAR/" 2>/dev/null
    fi
  done
done

# 3) Identify cloudsync/syncd-themed persistence entries
echo "[+] Hunting CloudSyncD-themed persistence" | tee -a "$LOG"
for d in /Library/LaunchAgents /Library/LaunchDaemons /Users/*/Library/LaunchAgents; do
  for f in "$d"/*loud*ync* "$d"/*yncd*; do
    [ -f "$f" ] || continue
    case "$f" in *com.apple.*) continue;; esac
    echo "[!] SUSPICIOUS PLIST: $f" | tee -a "$LOG"
    cp -p "$f" "$QUAR/" 2>/dev/null
    launchctl bootout system "$f" 2>/dev/null || launchctl unload "$f" 2>/dev/null
    rm -f "$f"
    echo "[+] Unloaded and removed: $f (copy preserved in quarantine)" | tee -a "$LOG"
  done
done

# 4) Kill processes masquerading as Zoom or running from staging paths
echo "[+] Enumerating suspicious running processes" | tee -a "$LOG"
ps auxww | grep -Ei 'cloudsync|syncd' | grep -v grep | tee -a "$LOG"
for pid in $(ps auxww | awk '$11 ~ /(cloudsyncd|CloudSyncD)/ {print $2}'); do
  echo "[!] Killing PID $pid" | tee -a "$LOG"
  kill -9 "$pid" 2>/dev/null
done
ps auxww | grep -Ei 'zoom' | grep -Ev '/Applications/zoom.us.app|grep' | tee -a "$LOG"

# 5) Search for trojanized installer remnants in common staging paths
echo "[+] Searching staging paths for fake Zoom artifacts" | tee -a "$LOG"
find /private/tmp /var/folders /Users/Shared /Users/*/Downloads -maxdepth 3 \
  \( -iname '*zoom*.app' -o -iname '*zoom*.pkg' -o -iname '*cloudsyncd*' \) \
  -not -path '*/zoom.us.app/*' 2>/dev/null | tee -a "$LOG"

# 6) Verify code signatures on any surviving Zoom-named binaries
echo "[+] Verifying signatures on Zoom-named binaries" | tee -a "$LOG"
find / -maxdepth 5 -iname 'zoom*.app' 2>/dev/null | while read -r app; do
  codesign -dv --verbose=2 "$app" 2>&1 | grep -E 'Authority|TeamIdentifier' | tee -a "$LOG"
  codesign -v "$app" 2>/dev/null || echo "[!] INVALID/MISSING SIGNATURE: $app" | tee -a "$LOG"
done

echo "[+] Triage complete. Artifacts preserved in $QUAR — collect before remediation" | tee -a "$LOG"

If step 2 or step 3 fires, treat the host as compromised: capture the quarantine bundle, acquire memory if your tooling supports it, and force a credential reset for the affected user — the entire point of this malware's phishing dialog is password capture, and the zero-width obfuscation means you should assume the password left the box even if you cannot locate the exfil record.

Remediation

Because CloudSyncD exploits trust rather than a software flaw, remediation is layered: contain the host, close the delivery path, and harden the fleet against the technique class.

Immediate (infected or suspected hosts):

  1. Isolate the endpoint from the network (MDM network isolation or physical disconnect) before running triage, to sever any live C2 channel.
  2. Run the triage script above; preserve the quarantine bundle for forensic analysis before wiping anything.
  3. Reset the user's credentials immediately — local account, and any enterprise IdP/SSO password that may have been entered into the fake dialog. Review IdP sign-in logs for post-compromise authentication anomalies. If the phished password was reused anywhere (it usually is), expand the reset scope.
  4. Rotate any secrets accessible from the host: SSH keys, cloud CLI tokens (~/.aws, ~/.azure, ~/.config/gcloud), browser-stored credentials, and keychain items for service accounts.
  5. Reimage from known-good media if persistence artifacts or unsigned payloads are confirmed. Do not rely on LaunchAgent removal alone against a backdoor under active development.

Fleet hardening:

  1. Enforce Gatekeeper and notarization — verify via spctl --status that Gatekeeper is enabled fleet-wide, and use your MDM to block overrides. CloudSyncD's fake installer cannot pass notarization; user right-click-open is the only way through, which leads to the next control.
  2. Deploy application allowlisting (Santa, Jamf Protect behavioral controls, or your EDR's equivalent) to block unsigned binaries executing from /tmp, /var/folders, ~/Downloads, and /Users/Shared.
  3. Block the delivery vector at the perimeter: alert on and consider blocking downloads of executables/disk images from domains impersonating Zoom (anything that isn't zoom.us and its documented CDN). Pair with DNS-layer filtering for newly registered Zoom-lookalike domains.
  4. Deploy the detections above. The osascript hidden-answer dialog rule catches this entire malware family — Atomic Stealer, Cthulhu, CloudSyncD, and their successors all share the fake-prompt technique because macOS offers few other ways to phish a GUI password convincingly.
  5. Monitor LaunchAgent/LaunchDaemon writes fleet-wide. Any plist write by a process that isn't a signed, expected installer package should page the SOC.
  6. User awareness: brief users that legitimate macOS software updates do not arrive via meeting-invite download links, and that any unexpected password dialog during an "update" should be reported, not completed.

Reference: Jamf Threat Labs' original disclosure (via Security Affairs): https://securityaffairs.com/200293/malware/fake-zoom-installer-hides-macos-backdoor-cloudsyncd.html — monitor for follow-on reporting, as Jamf assessed this family as actively under development and new builds are expected.

Related Resources

Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.