{
  "id": 11181496,
  "title": "This fake Mac Zoom installer has a sneaky way to bypass Gatekeeper",
  "url": "https://urgent.news/2026/10/01/this-fake-mac-zoom-installer-has-a-sneaky-way-to-bypass-gatekeeper",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T11:39:20.000Z",
  "source": {
    "name": "9to5Mac",
    "slug": "9to5mac",
    "url": "https://9to5mac.com/2026/10/01/this-fake-mac-zoom-installer-has-a-sneaky-way-to-bypass-gatekeeper/"
  },
  "original_language": "en",
  "account": "A fake Mac installer for Zoom, a videoconferencing application, has been found by cybersecurity firm Jamf that tricks Apple's Gatekeeper security feature. The malicious software, dubbed CloudSyncD, installs both Zoom and an infostealer designed to steal user data. Usually, macOS blocks installation of apps lacking notarization from Apple, but attackers have devised a method to convince users to bypass this security measure. The installer dropper contains a background image with step-by-step instructions, appearing as an ordinary Mac installer. Users are directed to open System Settings, navigate to Privacy & Security, and click \"Open Anyway\" – ultimately granting the malware administrator access. This unique approach to evading Gatekeeper sets it apart from other security threats. Once installed, CloudSyncD can capture user-entered information and transmit it to the attackers at regular intervals, potentially every eight seconds. To avoid falling victim to this kind of attack, users should only download Mac applications from the official Mac App Store or trusted developer sources. For further Apple news, consult 9to5Mac on YouTube.",
  "summary": "Cybersecurity company Jamf has discovered a fake Mac installer for the videoconferencing app Zoom that uses a sneaky way to bypass Apple’s Gatekeeper protection against malware . The malware does actually install Zoom , but also an infostealer that captures data and sends it to the attacker’s server … more…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}