As reported by SecurityAffairs, Jamf Threat Labs has identified a new macOS malware strain dubbed CloudSyncD, delivered through a fraudulent Zoom installer and employing a notably clever technique to exfiltrate user credentials: hiding stolen passwords inside invisible zero-width Unicode characters within a seemingly innocuous JSON configuration file.

Threat Alert: That compressed timeline suggests either a well-resourced operation with pre-existing infrastructure or a threat actor reusing components from prior campaigns.

What makes this campaign worth paying attention to is not any single technique — most of the individual components are well-established macOS intrusion methods — but rather how quickly the operator moved from an unfinished build on September 15 to live command-and-control infrastructure within 48 hours. That compressed timeline suggests either a well-resourced operation with pre-existing infrastructure or a threat actor reusing components from prior campaigns. Either way, it indicates the macOS threat landscape is maturing rapidly.

The Zero-Width Unicode Trick Deserves Attention

The use of zero-width spaces (U+200B) and zero-width non-joiners (U+200C) as positional markers within a fake settings file is a technique more commonly seen in phishing lures and covert channel communication than in credential exfiltration. By embedding 48 invisible characters after a visible version string, the malware encodes the offset and length of a base64-encoded password buried within random filler text. To any automated scanner or human reviewer, data.json looks like ordinary application preferences with theme and language settings.

This is steganography as persistence evasion — not just hiding the password from the victim, but hiding it from the victim's security tooling as well.

Security teams should recognize that this technique is trivially extensible. Zero-width Unicode can carry arbitrary data in any text field across any file format. DLP tools, EDR agents, and file content scanners that parse but do not sanitize Unicode are effectively blind to this method. Expect to see it adopted more broadly.

Gatekeeper Bypass Remains the Primary Initial Access Vector

The ad-hoc signed application package relies on social engineering the user through Gatekeeper bypass instructions displayed in the DMG background image. This is the same pattern seen in Bundlore, Shlayer, and virtually every notable macOS malware family of the past five years. Apple's notarization requirements have raised the bar, but ad-hoc signing combined with visual user guidance remains effective because macOS still allows users to override protections with an administrator password.

The password phishing dialog that repeatedly appears until a valid credential is entered — validated via dscl against the local account — is particularly effective because it appears in a context the user expects: installing software. Users trained to enter credentials during legitimate installations are conditioned to comply.

Fileless Execution Failure Is Instructive

CloudSyncD attempts to execute its universal Mach-O payload directly from memory via an anonymous file descriptor, which would avoid writing to disk entirely. System Integrity Protection (SIP) blocked this on most Macs, forcing a fallback to a temporary file on disk. This is a useful defensive data point: SIP continues to provide meaningful protection against memory-only execution techniques, but the fallback path means defenders still need endpoint detection covering the /tmp directory and temporary file execution.

Shield53 Recommendations

  • Deploy EDR with Unicode-aware scanning: Ensure your macOS endpoint protection can detect and flag files containing zero-width Unicode characters in unexpected locations, particularly JSON and plist files in application support directories.
  • Enforce strict Gatekeeper and notarization policies: Use MDM to prevent execution of ad-hoc signed applications. Devices where users have administrative rights remain the primary exposure.
  • Monitor dscl usage: Legitimate applications rarely need to query directory services for password validation. Alert on dscl . -auth or equivalent authentication attempts from unexpected processes.
  • Block known C2 infrastructure: Jamf has published indicators of compromise. Update network blocklists and proxy configurations accordingly.
  • User awareness training: Specifically address the Zoom installer DMG lure pattern. Legitimate Zoom installation comes from zoom.us/download or the Mac App Store — not from third-party download links.
  • Review SIP enforcement posture: While SIP blocked fileless execution here, verify it is enabled across your fleet. Disabled SIP dramatically increases exposure to memory-resident techniques.

The broader implication is that macOS is no longer flying under the radar. Threat actors are investing in platform-specific techniques, rapid infrastructure deployment, and evasion methods borrowed from other ecosystems. Organizations that treat macOS as inherently secure by design are accepting a risk that the current threat landscape no longer supports.