logo

CloudZ Malware Abuses Phone Link to Steal SMS OTPs

ID: 51d96d69-a4eb-59f0-8b1f-1e671bb3ca15

STIX ID: report--51d96d69-a4eb-59f0-8b1f-1e671bb3ca15

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

...
...

Cisco Talos researchers reported a Windows malware campaign active since at least January 2026 using a .NET RAT called CloudZ and a previously undocumented plugin named Pheno to hijack Microsoft Phone Link and exfiltrate SMS messages and OTPs from local Phone Link SQLite databases; the attack chain includes a Rust loader, regasm-based persistence, obfuscation/anti-analysis, staged C2/Pastebin configuration, and published IOCs and signatures to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.