The fake Zoom installer discovered by Jamf is stealing data by forcing Mac users to bypass Gatekeeper defenses. What you need to know to stay safe.
Cybersecurity firm Jamf has revealed that a fake Mac installer for the popular video conferencing app Zoom uses a sneaky system to bypass Apple’s Gatekeeper security measures. This malicious software, named CloudSyncD, infiltrates users’ systems by tricking them into believing they are installing a legitimate application.
To bypass Gatekeeper defenses, attackers design disk images containing visual instructions that lead users to make manual changes to system settings. Cybercriminals who succeed with this formula both run the real Zoom application on the system and create a dangerous backdoor that steals user data in the background and transmits it to their own servers at regular intervals.
How Do Attackers Bypass Gatekeeper Protection?
Apple’s Gatekeeper feature aims to protect Mac users from malicious software by preventing the execution of unapproved applications. However, CloudSyncD attackers have developed a rather cunning social engineering formula to bypass this protection.
Victims who open the fake software are presented with a disk image. This image provides a step-by-step guide instructing users to go to the “Settings” menu and click the “Open Anyway” button under the “Security” tab.
Users are essentially disabling their own firewall. This leaves the system vulnerable and allows malicious software to be installed without any problems. The scammers’ method is to convince the victim that they have solved a technical problem.
How Does the Software Steal Data?
When the malicious software becomes active on the system, it not only installs the legitimate version of Zoom but also activates an infostealer function. This malware collects sensitive information by monitoring user activity on the system. The collected information is sent periodically to command and control servers controlled by the attackers.
Analyzes by Jamf show that this process is quite fast, with information being updated every eight seconds. Such frequent data transmission can lead to the consumption of system resources and also create a basis for the rapid exchange of personal information. The application icon looking identical to the real Zoom is one of the biggest factors that makes it difficult for users to realize what is happening.
What Should Be Done for a Secure Mac Experience?
The most basic rule for Mac users to protect themselves from these types of threats is to obtain applications only from official sources. Downloading software from sources other than Apple’s official App Store or the application developer’s own verified website carries significant risks to system security. In addition, you should always question whether it is a legal process when you are asked to manually change the operating system’s security settings.
Being wary of suspicious or unexpectedly received software is the first step in digital security. Never connect disk images from unknown or unreliable sources to your system, and never authorize unknown software with your administrator password.
Have you ever been at risk of being tricked by a fake application? You can share the extra precautions you take to protect your Mac systems from cyberattacks and your opinions on the matter in the comments section.