logo

New CloudZ RAT Campaign Targets Mobile Notifications via Phone Link Abuse

ID: ab102225-eb81-556e-9556-aa456debc7ae

STIX ID: report--ab102225-eb81-556e-9556-aa456debc7ae

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Varshini

...
...

Cisco Talos identified an active campaign (since at least January 2026) using a modular remote access tool, CloudZ RAT, and a Pheno plugin to harvest credentials and intercept OTPs by leveraging the Microsoft Phone Link app’s local synchronization database. The attackers deliver the threat via a fake ScreenConnect update that installs a Rust dropper and a .NET in-memory loader, persist via a scheduled task and regasm, retrieve C2 configurations from Pastebin, and use Pheno to detect Phone Link connections and read SMS/authenticator notifications without infecting the mobile device.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.