CloudZ RAT Abuses Microsoft Phone Link to Steal SMS OTPs and Mobile Notifications
ID: 51d18340-b99e-5885-99d1-a6c37b7a5664
STIX ID: report--51d18340-b99e-5885-99d1-a6c37b7a5664
Feed Name: cybersecurityNews.com
Researchers at Cisco Talos identified an active campaign (since at least January 2026) deploying the CloudZ RAT and a novel Pheno plugin that abuse the Windows Phone Link bridge to silently exfiltrate SMS messages, OTPs and other phone-synced data without touching the device. The campaign uses a fake ScreenConnect update to drop a Rust-compiled loader and .NET payload, employs living-off-the-land techniques (regasm.exe, scheduled tasks), in-memory function generation and analysis-detection checks, and hosts secondary C2/configuration on services like Pastebin; the report includes IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
