Tendvane

← All articles

SecurityOctober 3, 2026

The Zoom installer asked for your password. The real one never does.

A file turns up called Zoom. You are about to join a call, so you open it, follow the steps, and partway through a box appears asking you to enter your password to allow this. You type it in. That is the entire attack.

Jamf Threat Labs published the details on 30 September. The malware is called CloudSyncD, it goes after Macs, and the first sample surfaced on 15 September looking half-built; within two days whoever is behind it had moved to live servers. The password you type gets checked against your real account, then buried inside a fake Zoom configuration file, with 48 invisible Unicode characters marking where it is hidden. The installer uses it to launch a backdoor with administrator rights. That backdoor then calls home every 8 to 16 seconds and waits to be told what to do.

What makes this worth reading on a Windows site is the lure rather than the code. Install Zoom to join the call is a staple of fake recruiter and fake client approaches, and the Windows version is the same evening with a different filename. In the past few weeks we have covered a fake Spotify installer and a payroll app that never existed. Jamf's own conclusion is blunt: for all the engineering, the attack still rests on the oldest technique there is, talking someone into handing over their password.

Treat an unexpected password prompt during a download as the moment to stop. Installers for Zoom, Teams or anything else come from the company's own site, and if a stranger sent you the link, the meeting can wait ten minutes. If you are unsure what a recent download left behind, Tendvane's safety check for unwanted software will show you what is now set to run on your PC.

Sources

Download Tendvane