This fake Mac Zoom installer has a sneaky way to bypass Gatekeeper
9to5mac.com Oct 1, 2026

This fake Mac Zoom installer has a sneaky way to bypass Gatekeeper

AI-summarised brief · reviewed before publication

Cybersecurity firm Jamf uncovered a counterfeit Zoom installer targeting macOS users. The malicious disk image masquerades as a legitimate Zoom setup, complete with an application icon and an alias to Applications. Its background image instructs users to bypass Gatekeeper by opening System Settings, selecting “Open Anyway,” and entering an administrator password. Once executed, the installer installs Zoom and an infostealer that exfiltrates data every eight seconds to the attacker’s server. The tactic exploits users’ willingness to follow seemingly normal installation steps.

💡 Why It Matters

  • · The attack demonstrates how attackers can manipulate familiar user interfaces to subvert macOS security, underscoring the need for vigilance when installing non‑notarized software.