Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

OpenAI is reportedly preparing legal action against Apple. This isn’t the first time my partner has been burned.

Clawdmeter turns your Clawd code usage statistics into a small desktop dashboard

YouTube viewers watch 2 billion hours of short videos on TV every month

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CloudZ RAT exploits Windows Phone links to steal credentials and OTPs
Identity

CloudZ RAT exploits Windows Phone links to steal credentials and OTPs

By May 6, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 6, 2026Endpoint security/threat intelligence

Cybersecurity researchers have detailed an intrusion that involved the use of the CloudZ remote access tool (RAT) and an earlier undocumented plugin called Pheno to facilitate credential theft.

“Based on the functionality of the CloudZ RAT and Pheno plugin, it was intended to steal victims’ credentials and potentially one-time passwords (OTPs),” Cisco Talos researchers Alex Karkins and Chetan Raghuprasad said in an analysis on Tuesday.

What makes this attack novel is that CloudZ uses a custom Pheno plugin to hijack the PC-to-phone bridge established by exploiting the Microsoft Phone Link application, allowing the plugin to monitor active Phone Link processes and potentially intercept sensitive mobile data such as SMS and one-time passwords (OTPs) without introducing malware to the phone.

Our findings demonstrate how legitimate cross-device synchronization capabilities can help expose unintended attack vectors to credential theft and bypass two-factor authentication. Additionally, it eliminates the need to compromise the mobile device itself.

The malware has been used as part of an intrusion that has been active since at least January 2026, according to the cybersecurity firm. This activity is not attributed to any known attacker or group.

Built into Windows 10 and Windows 11, Phone Link provides a way for users to pair their computer with an Android device or iPhone over Wi-Fi and Bluetooth, allowing users to make and receive calls, send messages, dismiss notifications, and more.

An unknown attacker has been observed leveraging applications using the CloudZ RAT and Pheno to view phone link activity in the victim environment and attempt to access the SQLite database files used by the program to store synchronized phone data.

This attack chain allegedly gained a foothold using a yet-to-be-determined initial access method and dropped a fake ConnectWise ScreenConnect executable that was responsible for downloading and running the .NET loader. The first dropper also leverages an embedded PowerShell script to establish persistence by setting up a scheduled task to run the malicious .NET loader.

The intermediate loader is designed to perform hardware and environmental checks to evade detection and deploy the modular CloudZ Trojan onto machines. When executed, the .NET-compiled Trojan waits for Base64-encoded instructions that allow it to decrypt embedded configurations, establish an encrypted socket connection to a command and control (C2) server, steal credentials, and embed additional plugins.

Commands supported by CloudZ include:

pong, PING! to send a heartbeat response, CLOSE to issue a heartbeat request, INFO to terminate the Trojan process, RunShell to collect system metadata, execute shell command BrowserSearch, GetWidgetLog to extract web browser data, plugin to extract Phone Link reconnaissance logs and data, savePlugin to load plugins, Staging Save the plugin to disk in the directory (“C:\ProgramData\Microsoft\whealth\”) sendPlugin, uploads the plugin to the C2 server RemovePlugins, removes all deployed plugin modules Recovery, enables recovery or reconnection DW, performs download and file write operations FM, performs file management operations Msg, sends a message to the C2 server Error, reports an error to the C2 server rec, record the screen

“The attackers used a plugin called Pheno to spy on the Windows Phone Link application on the victim machine,” Talos said. “The plugin performs reconnaissance of the Microsoft Phone Link application on the victim machine and writes the reconnaissance data to an output file in the staging folder. CloudZ reads back the Phone Link application data from the staging folder and sends it to the C2 server.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFDA finds low levels of chemical contamination in U.S. infant formula
Next Article UK drone sector to expand significantly with £46.5m funding

Related Posts

Cisco Catalyst SD-WAN Controller Authentication Bypass Is Actively Abused to Gain Administrative Access

May 14, 2026

Stealer backdoor targeting developer secrets found in three node IPC versions

May 14, 2026

PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories

May 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

OpenAI is reportedly preparing legal action against Apple. This isn’t the first time my partner has been burned.

Clawdmeter turns your Clawd code usage statistics into a small desktop dashboard

YouTube viewers watch 2 billion hours of short videos on TV every month

Cisco Catalyst SD-WAN Controller Authentication Bypass Is Actively Abused to Gain Administrative Access

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.