Cybersecurity firm Jamf has discovered a fake installer for the video conferencing app Zoom on Mac that uses a cunning way to bypass Gatekeeper against malware. Gatekeeper is a key macOS security feature that prevents unverified applications from running, ensuring that users only install software that has been reviewed and approved by Apple.
See also: BlueNoroff distributes MacOS malware via deepfake videos in Zoom meetings

However, attackers have found ways to bypass this system by exploiting user interaction. The malware, known as CloudSyncD, installs Zoom but also includes an infostealer, a type of malware that records data and sends it to the attacker’s server. This software can collect sensitive information, such as passwords, personal data, and other information entered by the user, and send it to the attackers as often as every eight seconds.
Normally, when you try to install a Mac app that hasn't been certified by Apple, macOS refuses to open it. There is a way to allow the installation, but it requires user intervention, and attackers have to convince users to follow this process. This is achieved through social engineering, where users are tricked into performing actions they wouldn't normally do.
The criminals behind the malware have found a clever way to make the installation process look more normal. The application installer includes a background image with instructions. CloudSyncD arrives as a disk image that mounts as a volume named Zoom, designed to look like any regular Mac installer: an application icon on the left and a shortcut to Applications on the right.
The background image contains a numbered list of Settings that instructs the victim to open System Settings, go to the Privacy & Security, scroll to the Security, click Open Anyway , and enter their administrator password. These instructions are intended to bypass Gatekeeper.
See also: M5 Max Mac Studio review: A much better option than the Ultra

This process exploits users' trust in well-known applications, such as Zoom, and the lack of technical knowledge that some users may have regarding the software installation process. Users are often unfamiliar with the details of system security and may not realize that they are following instructions that put their data at risk.
This threat has significant consequences for users and organizations. Users who fall victim to this malware can see their personal data stolen and used for malicious purposes, such as identity theft or financial fraud. Organizations, on the other hand, can face serious data breaches, which can lead to loss of customer trust and legal consequences.
To protect against such threats, users should be extra careful when installing software and ensure that it comes from trusted sources. It is important to only install Mac apps from the official Mac App Store or from developer websites that you trust. Additionally, users should be wary of any instructions that ask them to bypass macOS security systems.
See also: The new Mac Mini has two storage drawbacks

Jamf’s discovery of the fake Zoom installer highlights the importance of continuously informing and educating users about cybersecurity threats. Users must stay informed about the latest techniques attackers use to bypass security systems and protect their data. Partnering with reputable cybersecurity companies and using up-to-date security software can go a long way in preventing such attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
