CloudZ RAT Hijacks Phone Link to Steal SMS OTPs via Pheno Plugin

1 min read
Source: BleepingComputer
CloudZ RAT Hijacks Phone Link to Steal SMS OTPs via Pheno Plugin
Photo: BleepingComputer
TL;DR Summary

A new CloudZ RAT variant, equipped with a Pheno plugin, monitors active Microsoft Phone Link sessions and accesses the local Phone Link SQLite database to harvest SMS messages and one-time passwords, enabling credential theft without compromising the mobile device. Infections begin with a fake ScreenConnect updater that drops a Rust loader, followed by a .NET loader to install the RAT and establish persistence, with anti-analysis checks to evade sandboxes. Defenders are advised to avoid SMS-based OTPs in favor of non-push authenticators or hardware keys; Cisco Talos has published IO and indicators of compromise.

Share this article

Reading Insights

Total Reads

0

Unique Readers

18

Time Saved

4 min

vs 5 min read

Condensed

89%

83793 words

Want the full story? Read the original article

Read on BleepingComputer