
Malware called CloudSyncD disables Apple's Gatekeeper protection through social engineering.
AI-generated summary
Apple's Gatekeeper feature aims to protect Mac systems by preventing unapproved applications from running.
Fake Zoom installer, discovered by Jamf, forces Mac users to bypass Gatekeeper protection and steal their data. What you need to know to stay safe.
Cybersecurity firm Jamf has revealed that a fake Mac installer for the popular video conferencing app Zoom uses a sneaky method to bypass Apple's Gatekeeper security measures. This malware, called CloudSyncD, infiltrates users' systems by tricking them into believing they are installing a legitimate application.
To bypass Gatekeeper protection, attackers design disk patterns that contain visual instructions that direct users to make manual changes to system settings. Cybercriminals who are successful with this method both run the real Zoom application on the system and create a dangerous backdoor that steals user data in the background and transmits it to their own servers at regular intervals.
How Do Attackers Bypass Gatekeeper Protection?
Apple's Gatekeeper feature aims to protect Mac users from malware by preventing unnotarized (unapproved) applications from running. However, CloudSyncD attackers have developed a very cunning social engineering method to bypass this protection.
Victims who open the fake installation file are presented with a disk image. This image provides users with a step-by-step guide to go to the “Settings” menu and click the “Open Anyway” button via the “Security” tab.
Users actually disable the firewall with their own hands. This leaves the system vulnerable and allows malware to be installed unhindered. This method of fraudsters is based on convincing the victim that they have solved a technical problem.
How Does Software Leaking into the System Steal Data?
Once the malware becomes active on the system, it not only installs the legitimate version of Zoom but also launches an information stealer (infostealer) function. This malware collects sensitive information by monitoring user movements in the system. The obtained data is sent periodically to command and control servers controlled by the attackers.
Analysis by Jamf shows that this process is quite fast, with data updated every eight seconds. Such frequent data transmission may consume system resources and also pave the way for personal information to change hands rapidly. The fact that the application icon looks the same as the real Zoom is one of the biggest factors that makes it difficult for users to realize the situation.
What Should Be Done for a Safe Mac Experience?
The most basic rule for Mac users to protect themselves from such threats is to obtain applications only from official sources. Downloading software from sources other than Apple's official App Store or the application developer's own verified website poses great risks to system security. Additionally, whenever you are asked to manually change the operating system's security settings, you should always question whether this is a legitimate action.
Being wary of installation files that look suspicious or arrive unexpectedly is the first step to digital security. Never connect disk images to your system from unknown or unreliable sources, and do not approve unknown software with your administrator password.
HAVELSAN is implementing the artificial intelligence-supported 'EYEMINER' early warning system in schools with the protocol signed with the Governorship at TEKNOFEST held in Şanlıurfa. General Manager Mehmet Akif Nacar stated that they aim to instill technology vision in young people.

Sony's new handheld console, codenamed 'Canis', aims for high energy efficiency and compact design with TSMC's N3P production technology. The device aims to offer long battery life and portability without the need for heavy cooling systems.

Proofpoint announced that the China-linked TA419 hacker group impersonated former government officials, targeting US artificial intelligence experts with fake cooperation offers and trying to steal their passwords.

Microsoft co-founder Bill Gates emphasized that the next 5 years are critical, stating that if the necessary precautions are not taken, the biological, cyber and psychosocial risks of artificial intelligence may emerge faster than its benefits.

Huawei introduced the new generation Alpha 6000 antenna system with digital twin support at the Global Antenna Technology and Industry Forum. The system increases data transmission capacity while simplifying installation in U6G networks.

The Netherlands is developing the Linux-based public operating system DAWO following concerns about technological dependency and US ICC sanctions. The project, which is piloting in 8 municipalities, is planned to be opened in 2027.