CloudSyncD Reused a Mac Password to Launch
Jamf’s 30 September report, with no publication time, describes CloudSyncD in a fake Zoom installer. A development sample appeared 15 September; live-configured infrastructure followed within two days.
The fallback ran
The app required a Gatekeeper override, validated a password locally, hid it in data.json and reused it with sudo. Development and live builds used different paths. After the fileless method failed under System Integrity Protection, a temporary-file fallback executed and beaconed.
The report did not establish persistence, a victim count or actor. The report identifies no Zoom flaw or CVE and does not support a broad password-never-stored claim. Isolate affected Macs, rotate credentials and block the published infrastructure.
Sources and context
- Jamf report, 30 September 2026.
- Context: AmnesiaStealer and MacSync are distinct malware.


