Jamf Threat Labs reported CloudSyncD, a new macOS backdoor that spreads through a fake Zoom installer and beacons to its server every 8 to 16 seconds. First caught as a VirusTotal sample that looked unfinished, it now appears in builds that connect to live infrastructure in what Jamf calls an active campaign.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption15
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Jamf Threat Labs says the Rust macOS stealer pastes itself in via Terminal, fakes an Installer password prompt, mutes the speakers, then hands the operator a headless clone of your logged-in profile.
Perspective Coverage
5 publishers
- Builder
- Builder 30%
- Operator
- Operator 65%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
Jamf Threat Labs found a PamStealer build that completes a server key exchange before its macOS payload decrypts, so captured samples cannot be recovered offline. It also layers four persistence methods and a Swift stealer that harvests keychains and credentials from 13 browsers.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence62
The StopAndProtect campaign keeps its payloads, command channel and stolen-file storage on other people's blogs. That makes domain reputation a weaker signal, and cleanup somebody else's bill.
Reality
- Evidence66
- Adoption68
- Hype gap+14
- Incentives61
- Confidence64
Jamf Threat Labs describes a Rust stealer that copies Chromium profiles and drives them over Chrome DevTools Protocol. Password rotation does not revoke what it exports.
Reality
- Evidence64
- Adoption18
- Hype gap+14
- Incentives52
- Confidence58