news.mlab.sh
Back to the feed
threat-intel

CloudZ RAT potentially steals OTP messages using Pheno plugin

High
Image: Cisco Talos
Summary

Cisco Talos identified an intrusion campaign initiated in January 2026 involving the deployment of the CloudZ remote access tool (RAT) alongside a new plugin called ‘Pheno.’ This campaign leveraged the Microsoft Phone Link application to intercept OTP messages and potentially steal credentials by monitoring the application’s SQLite database. The attacker used a staged dropper and a Rust-compiled executable to achieve initial access and establish a persistent presence on compromised systems.

Read the full article at Cisco Talos

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.