logo

New “Pheno” Malware Hijacks Microsoft Phone Link to Steal SMS and OTPs

ID: 8a783da0-66e9-561b-9857-b2e7a3255c0e

STIX ID: report--8a783da0-66e9-561b-9857-b2e7a3255c0e

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

Cisco Talos reports an active campaign (since at least Jan 2026) in which the CloudZ RAT and a specialized Pheno plugin abuse Microsoft Phone Link on compromised Windows hosts to intercept synchronized SMS, call logs, and OTPs from system memory, enabling OTP/2FA bypass without installing malware on the phone; the tools use memory-only execution and anti-forensic checks to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.