
CloudZ RAT Hijacks Phone Link to Steal SMS OTPs via Pheno Plugin
A new CloudZ RAT variant, equipped with a Pheno plugin, monitors active Microsoft Phone Link sessions and accesses the local Phone Link SQLite database to harvest SMS messages and one-time passwords, enabling credential theft without compromising the mobile device. Infections begin with a fake ScreenConnect updater that drops a Rust loader, followed by a .NET loader to install the RAT and establish persistence, with anti-analysis checks to evade sandboxes. Defenders are advised to avoid SMS-based OTPs in favor of non-push authenticators or hardware keys; Cisco Talos has published IO and indicators of compromise.











