Experts warn Microsoft Phone Link tool exploited by ‘unknown threat’ to steal SMS and OTP info



  • A new CloudZ plugin, Pheno, hijacks Microsoft Phone Link to steal SMS and OTPs from connected Android devices
  • This enables attackers to bypass 2FA without compromising the phone itself
  • The RAT retains full remote access capabilities, with researchers urging a shift away from SMS‑based authentication

A new version of the CloudZ remote access trojan (RAT) for Windows now comes with a new plugin that steals data from a connected Android device, experts have revealed.

Security researchers Cisco Talos recently spotted the upgraded variant while investigating a breach that has been ongoing since January 2026.

https://cdn.mos.cms.futurecdn.net/HXss3QE8EHbLLCL7ma37sK-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img