CloudZ RAT Exploits Microsoft Phone Link to Steal SMS OTPs
ID: f9158b31-01a7-5078-a2b9-d6dfe7e977e1
STIX ID: report--f9158b31-01a7-5078-a2b9-d6dfe7e977e1
Feed Name: GBHackers
CloudZ is a modular .NET remote access trojan observed since at least January 2026 that, together with a Pheno plugin, abuses Microsoft Phone Link to capture SMS OTPs and mobile notifications mirrored to Windows PCs. Cisco Talos describes an infection chain beginning with a fake ScreenConnect update that deploys a Rust loader and a .NET loader, establishes persistence via a scheduled task and regasm LOLBin, uses extensive anti‑analysis and in‑memory techniques, connects to encrypted C2, and exfiltrates Phone Link databases and reconnaissance logs, allowing attackers to intercept authentication flows without infecting the mobile device.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
