logo

CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs

ID: 233321d3-604c-59bb-9a95-3eb550e42512

STIX ID: report--233321d3-604c-59bb-9a95-3eb550e42512

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Bill Toulas

...
...

Cisco Talos researchers discovered a CloudZ RAT variant using a new Pheno plugin that monitors Microsoft Phone Link sessions and reads the local SQLite database to steal SMS messages and OTPs, enabling attackers to intercept authentication codes without compromising the mobile device; the report describes the Rust and .NET loaders, persistence via scheduled tasks, anti-analysis checks, additional RAT capabilities (file ops, shell execution, screen recording, plugin management), and published IoCs to help defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.