logo

Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs

ID: 80cceca2-c9fb-5ddb-9793-807caf6ebc96

STIX ID: report--80cceca2-c9fb-5ddb-9793-807caf6ebc96

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Cisco Talos researchers report an active intrusion (since at least Jan 2026) involving the CloudZ RAT and a Pheno plugin that abuses Microsoft Phone Link to read synchronized phone data (including SMS/OTPs) from the PC side without infecting the mobile device. The campaign uses a fake ConnectWise ScreenConnect executable to drop a .NET loader, establishes encrypted C2 communications, supports modular plugins and exfiltration commands, and stages data in a local folder (e.g., C:\ProgramData\Microsoft\whealth) to steal credentials and bypass two-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.