New CloudZ RAT Campaign Targets Mobile Notifications via Phone Link Abuse
ID: ab102225-eb81-556e-9556-aa456debc7ae
STIX ID: report--ab102225-eb81-556e-9556-aa456debc7ae
Feed Name: Cyber Press
Cisco Talos identified an active campaign (since at least January 2026) using a modular remote access tool, CloudZ RAT, and a Pheno plugin to harvest credentials and intercept OTPs by leveraging the Microsoft Phone Link app’s local synchronization database. The attackers deliver the threat via a fake ScreenConnect update that installs a Rust dropper and a .NET in-memory loader, persist via a scheduled task and regasm, retrieve C2 configurations from Pastebin, and use Pheno to detect Phone Link connections and read SMS/authenticator notifications without infecting the mobile device.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
