{"id":216136,"date":"2026-05-19T02:50:06","date_gmt":"2026-05-19T06:50:06","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/19\/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps\/"},"modified":"2026-05-19T02:50:10","modified_gmt":"2026-05-19T06:50:10","slug":"cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/19\/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps\/","title":{"rendered":"CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs"},"content":{"rendered":"<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps\/\">CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-05 06:03:52<\/a><\/p>\n<p>Source Domain: <a href=\"www.bleepingcomputer.com\">www.bleepingcomputer.com<\/a><\/p>\n<p><strong>Summary:<\/strong><br \/>\nThis article reveals Cisco Talos\u2019s discovery of a new malicious plugin named Pheno within the CloudZ remote access tool (RAT). The malware exploits the Microsoft Phone Link application, installed on Windows 10 and 11, to steal credentials and temporary passcodes from mobile devices without directly compromising the mobile device. Pheno monitors for active Phone Link sessions and accesses the application\u2019s local SQLite database to intercept sensitive codes sent via SMS. Alongside, CloudZ targets browsers for data extraction and carries out multiple operations including file management and shell command execution. The infection chain starts with a fake ScreenConnect update used to install a Rust-based loader that deploys a.NET loader for CloudZ RAT establishment. Cisco has published indicators of compromise to aid defenders in identifying and mitigating these threats. To combat such risks, users are advised to avoid SMS-based OTP services and use phishing-resistant solutions like hardware keys.<\/p>\n<p><strong>Key Points:<\/strong><\/p>\n<ul>\n<li>Discovery of a new malicious plugin, Pheno, within CloudZ RAT that targets Microsoft Phone Link to steal credentials and OTPs.<\/li>\n<li>Phishing-resistant solutions recommended to mitigate risks from such attacks, suggesting users to opt for hardware keys instead of SMS-based OTPs.<\/li>\n<li>CloudZ RAT not only targets Phone Link but also web browsers for data theft and supports several other functions like file management and shell command execution.<\/li>\n<li>The infection process starts with distributing a malicious ScreenConnect update that deploys a Rust-based loader followed by a.NET loader for establishing persistence.<\/li>\n<li>Cisco provides indicators of compromise to help organizations identify and defend against this threat.<\/li>\n<\/ul>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs https:\/\/www.bleepingcomputer.com\/news\/security\/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps\/ Publish Date: 2026-05-05&#8230;<\/p>\n","protected":false},"author":1,"featured_media":216137,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.bleepstatic.com\/content\/hl-images\/2026\/02\/13\/Windows_headpic.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[32,25],"class_list":["post-216136","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-malware","tag-phishing"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/216136"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=216136"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/216136\/revisions"}],"predecessor-version":[{"id":216138,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/216136\/revisions\/216138"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/216137"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=216136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=216136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=216136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}