BlackTree Security · Infrastructure · Automation · AI

CloudSyncD Reused a Mac Password to Launch

Jamf’s 30 September report, with no publication time, describes CloudSyncD in a fake Zoom installer. A development sample appeared 15 September; live-configured infrastructure followed within two days.

The fallback ran

The app required a Gatekeeper override, validated a password locally, hid it in data.json and reused it with sudo. Development and live builds used different paths. After the fileless method failed under System Integrity Protection, a temporary-file fallback executed and beaconed.

The report did not establish persistence, a victim count or actor. The report identifies no Zoom flaw or CVE and does not support a broad password-never-stored claim. Isolate affected Macs, rotate credentials and block the published infrastructure.

Sources and context

Leave a Reply

Your email address will not be published. Required fields are marked *