Malware Activity
Fake Zoom Installer Deploys New CloudSyncD macOS Backdoor
Jamf researchers have identified a new macOS backdoor called CloudSyncD that has recently moved from development into active deployment. The malware is delivered via social engineering as a fake Zoom installer where victims are lured into downloading a disk image that mounts as “Zoom” and running an installer they believe will install Zoom, but instead installs CloudSyncD. The dropper carries a full universal Mach-O payload, writes it to an anonymous file descriptor, and tries to execute it. When macOS System Integrity Protection blocks this, it temporarily writes the payload to disk and runs it with sudo using the user’s password collected during the “installation.” That password is not exfiltrated, but rather it is used locally to gain root and set up a persistent daemon named CloudSyncD. CloudSyncD stores its configuration encrypted, uses string obfuscation, disguises its beacon as a jQuery fetch to two (2) Cloudflare protected domains, and performs host profiling and data exfiltration, serving as a stealthy long term backdoor rather than a classic infostealer. Jamf has published extensive IOCs to help defenders detect it, which CTIX Analysts have linked below.
- Security Week: CloudSyncD macOS Backdoor Article
- Jamf Threat Labs: CloudSyncD macOS Backdoor Blog Post
Threat Actor Activity
China-Linked TA419 Impersonates AI Policy Experts in Targeted Phishing Campaigns
A China aligned espionage group, tracked by Proofpoint as TA419, is running targeted credential phishing campaigns against AI policy experts at US and Japanese think tanks, universities, defense contractors, and law firms. Since at least April 2025, the threat actor group has impersonated high profile figures, including a senior Anthropic employee to, invite targets to join a fake “AI Policy Advisory Committee” or contribute to a Senate foreign relations report on AI export controls and supply chains. If a victim replies, TA419 sends a shortened URL that leads through Cloudflare Turnstile and a fake OneDrive loading screen to an adversary in the middle (AitM) page built on the Frameless BitB kit and Evilginx phishlets. The reverse proxy forwards Microsoft 365/Entra ID logins in real time, capturing usernames, passwords, MFA codes, and session cookies, and automatically ticking “Keep me signed in” to extend session life. TA419 hides its infrastructure behind Cloudflare and uses dozens of file sharing themed and impersonation domains (driftshare[.]co, globalfileshareplatform[.]com). Proofpoint assesses the activity as intelligence gathering on US AI policy and broader defense and foreign policy issues. CTIX Analysts recommend phishing resistant, origin bound authentication (such as passkeys) and independent verification of unsolicited subject matter outreach.
- The Register: TA419 AI Spoofing Article
- Info Security: TA419 AI Spoofing Article
- Proofpoint: TA419 AI Spoofing Threat Insight Report
Vulnerabilities
Warlock Ransomware Exploits SharePoint to Target Critical Infrastructure Across Multiple Regions
The suspected China-linked Warlock ransomware group, also tracked as Longlegs, Gold Salem, and Storm-2603, continues to exploit Microsoft SharePoint vulnerabilities, including the ToolShell exploit chain, to target critical infrastructure, government, and education organizations across Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America. After compromising vulnerable on-premises SharePoint servers, Warlock operators deploy web shells, steal ASP.NET machine keys, forge signed payloads, and achieve remote code execution (RCE) before conducting reconnaissance and expanding access throughout victim networks. The group combines DLL sideloading and living-off-the-land techniques with legitimate cloud services, Visual Studio Code tunneling for remote access, and tools such as NetExec for Active Directory enumeration, credential spraying, and command execution. Warlock also uses a BYOVD technique involving the vulnerable K7RKScan.sys driver (CVE-2025-1055) to disable AV/EDR defenses; in one critical-infrastructure intrusion, security protections were disabled on at least forty (40) hosts within roughly two (2) hours before ransomware was deployed to at least thirty-three (33) systems. Attackers staged the ransomware in the domain SYSVOL share to leverage domain replication for network-wide distribution, demonstrating Warlock’s ability to rapidly transition from initial SharePoint exploitation to large-scale ransomware deployment. Researchers warn that ToolShell and other SharePoint vulnerabilities remain effective initial-access vectors against unpatched deployments, while Warlock’s recent geographic concentration may reflect either opportunistic exploitation of exposed systems or deliberate targeting of Portuguese- and Spanish-speaking organizations.
- Bleeping Computer: SharePoint Vulnerabilities Article
- The Hacker News: SharePoint Vulnerabilities Article
- The Record: SharePoint Vulnerabilities Article
📧 Never Miss a Briefing
Stay informed and secure. Subscribe to Ankura’s Cyber Flash Update, a bi-weekly briefing curated by our top cybersecurity experts. Receive timely insights on emerging threats, vulnerabilities and malicious actors to keep your systems secure.
Join the Cyber Flash Update community today.
© Copyright 2026. The views expressed herein are those of the author(s) and not necessarily the views of Ankura Consulting Group, LLC., its management, its subsidiaries, its affiliates, or its other professionals. Ankura is not a law firm and cannot provide legal advice.
