Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
ID: 80cceca2-c9fb-5ddb-9793-807caf6ebc96
STIX ID: report--80cceca2-c9fb-5ddb-9793-807caf6ebc96
Feed Name: The Hacker News
Cisco Talos researchers report an active intrusion (since at least Jan 2026) involving the CloudZ RAT and a Pheno plugin that abuses Microsoft Phone Link to read synchronized phone data (including SMS/OTPs) from the PC side without infecting the mobile device. The campaign uses a fake ConnectWise ScreenConnect executable to drop a .NET loader, establishes encrypted C2 communications, supports modular plugins and exfiltration commands, and stages data in a local folder (e.g., C:\ProgramData\Microsoft\whealth) to steal credentials and bypass two-factor authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
