Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA
ID: f91374a1-8574-5bb3-853b-be6a35354a8c
STIX ID: report--f91374a1-8574-5bb3-853b-be6a35354a8c
Feed Name: Dark Reading
Threat Score
Cisco Talos describes an ongoing campaign where attackers deliver the CloudZ RAT and a novel Pheno plug-in to Windows machines to abuse the Phone Link (Your Phone) cross-device sync, enabling interception of SMS messages and OTPs from paired mobile devices without deploying mobile malware; researchers observed deployment artifacts, provided IoCs and detection guidance, and warned this can enable 2FA bypass.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
