AI News Feed
Market watch
Cybersecurity

Fake Mac Zoom Installer Uses Background Instructions to Bypass Gatekeeper, Jamf Finds

Jamf found a Mac Zoom installer, CloudSyncD, that tricks users into bypassing Gatekeeper and installs an infostealer.

The installer arrives as a disk image that mounts as a volume named Zoom, 9to5Mac reported. Its layout resembles a standard Mac installer: an application icon on the left and an alias to the Applications folder on the right. The difference is a background image containing a numbered Setup list. That list tells the victim to open System Settings, go to Privacy & Security, scroll to the Security section, click Open Anyway, and enter an administrator password.

Those steps are instructions to bypass Gatekeeper. Apple's macOS protection normally refuses to open apps Apple has not notarized. macOS does offer a workaround for users who want to run such software, but the process is fiddly, and attackers usually must persuade users to follow it. According to 9to5Mac, CloudSyncD tries to make that unusual process look like ordinary installation guidance.

The malware does install Zoom, the report said, but it also installs an infostealer. Once installed, the infostealer can record data users enter and send it to the attacker's server as frequently as every eight seconds.

9to5Mac said the fake installer's approach is creative, but the security advice remains unchanged: users should install Mac apps only from the official Mac App Store or from websites of developers they trust.