// 9TO5MAC — MOBILE & WEB
This fake Mac Zoom installer has a sneaky way to bypass Gatekeeper
Cybersecurity company Jamf has discovered a fake Mac installer for the videoconferencing app Zoom that uses a sneaky way to bypass Apple’s Gatekeeper protection against malware.
The malware does actually install Zoom, but also an infostealer that captures data and sends it to the attacker’s server …
Normally, when you try to install a Mac app that Apple hasn’t notarized, macOS will refuse to open it. There is a workaround to allow you to do so, but it’s somewhat fiddly, and attackers have to find some way to persuade users to do it.
The criminals behind the malware Jamf has dubbed CloudSyncD have found a clever way to make this seem more normal to users. The app installer dropper includes a background image with instructions, as shown above.
CloudSyncD arrives as a disk image that mounts as a volume named Zoom, laid out to look like any ordinary Mac installer: an application icon on the left, an alias to Applications on the right. The difference is the background image, which carries a numbered Setup list telling the victim to open System Settings, go to Privacy & Security, scroll to the Security section, click Open Anyway, and enter their administrator password. Those are instructions to bypass Gatekeeper.
Once the malware is installed, it can record user-entered data and send it to the attackers as frequently as every eight seconds.
As always, you should only ever install Mac apps from the official Mac App Store or the websites of developers you trust.
FTC: We use income earning auto affiliate links. More.