Jamf says a fake Zoom installer for macOS used invisible Unicode characters to hide a stolen password in a config file, enabling a backdoor. The hidden credential was then used by CloudSyncD to gain elevated access.