SecurityWeek reports that macOS users are being targeted by a fake Zoom installer carrying a backdoor dubbed CloudSyncD. The malicious installer is designed to look like a legitimate Zoom setup file, but instead of installing the video conferencing app, it drops malware onto the system.
The dropper carries a complete universal Mach-O binary inside itself—roughly 756 KB in the development build—and extracts it at runtime. This technique helps the malware avoid detection by keeping the payload hidden until execution. Once extracted, CloudSyncD provides backdoor access to the compromised Mac, allowing the attacker to run commands and control the machine remotely.
Because the source is a single report, there are no conflicting accounts. The key takeaway is that macOS users should be cautious when downloading installers from unofficial sources, as this campaign shows attackers are actively abusing trusted app names to deliver malware.