CloudZ Malware Abuses Phone Link to Steal SMS OTPs
ID: 51d96d69-a4eb-59f0-8b1f-1e671bb3ca15
STIX ID: report--51d96d69-a4eb-59f0-8b1f-1e671bb3ca15
Feed Name: Infosecurity Magazine (News)
Threat Score
Cisco Talos researchers reported a Windows malware campaign active since at least January 2026 using a .NET RAT called CloudZ and a previously undocumented plugin named Pheno to hijack Microsoft Phone Link and exfiltrate SMS messages and OTPs from local Phone Link SQLite databases; the attack chain includes a Rust loader, regasm-based persistence, obfuscation/anti-analysis, staged C2/Pastebin configuration, and published IOCs and signatures to aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
