threat-intel
CloudZ RAT potentially steals OTP messages using Pheno plugin
High
Summary
Cisco Talos identified an intrusion campaign initiated in January 2026 involving the deployment of the CloudZ remote access tool (RAT) alongside a new plugin called ‘Pheno.’ This campaign leveraged the Microsoft Phone Link application to intercept OTP messages and potentially steal credentials by monitoring the application’s SQLite database. The attacker used a staged dropper and a Rust-compiled executable to achieve initial access and establish a persistent presence on compromised systems.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
