logo

CloudZ RAT potentially steals OTP messages using Pheno plugin

ID: 45bc89f6-7e34-5fa7-b476-5ec8ac27ac94

STIX ID: report--45bc89f6-7e34-5fa7-b476-5ec8ac27ac94

Feed Name: Cisco Talos

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Alex Karkins

...
...

Cisco Talos reports an active intrusion (observed since at least January 2026) in which attackers deployed a modular .NET RAT named CloudZ and a Pheno plugin that monitors and abuses the Windows Phone Link application to exfiltrate browser credentials and potentially SMS/OTP messages; the intrusion chain involves a Rust-compiled dropper, an embedded .NET loader that performs evasion and establishes persistence via a scheduled task using regasm.exe, and C2/staging infrastructure hosted on Pastebin and worker domains, with IOCs and detection signatures provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.