Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CloudZ Malware Exploits Phone Link for Credential Theft

CloudZ Malware Exploits Phone Link for Credential Theft

Posted on May 6, 2026 By CWS

Cybersecurity experts have revealed a sophisticated cyberattack leveraging the CloudZ remote access tool (RAT) and an undocumented plugin named Pheno to facilitate credential theft. Researchers from Cisco Talos, Alex Karkins and Chetan Raghuprasad, have shed light on this intrusion aimed at stealing credentials and potentially intercepting one-time passwords (OTPs).

Novel Attack Vector Exploits Phone Link

This innovative attack exploits CloudZ’s custom Pheno plugin to hijack the communication bridge between PCs and phones by misusing Microsoft’s Phone Link application. The plugin can monitor active Phone Link processes, potentially intercepting sensitive data such as SMS and OTPs without needing to infect the phone itself. This strategy highlights the risks associated with cross-device syncing features, which can inadvertently open pathways for credential theft and bypass two-factor authentication.

Importantly, the attack does not require compromising the mobile device directly, showcasing how legitimate features can be manipulated for malicious purposes. This malware campaign has reportedly been active since January 2026, although it has not been attributed to any specific threat group.

Technical Details of the Attack Chain

Phone Link, integrated into Windows 10 and 11, enables users to connect their computers with Android or iOS devices via Wi-Fi and Bluetooth, facilitating calls and messages. Threat actors have been observed attempting to exploit this application using CloudZ RAT and Pheno by confirming Phone Link activity on victim systems and accessing the SQLite database used for storing synchronized data.

The attack begins with an unidentified initial access method, allowing the deployment of a fake ConnectWise ScreenConnect executable. This executable downloads and executes a .NET loader, incorporating a PowerShell script to establish persistence through a scheduled task. The intermediate loader conducts hardware and environment checks to avoid detection before deploying the modular CloudZ trojan.

Functionality and Impact of CloudZ RAT

Once active, the .NET-compiled trojan decrypts its configuration and connects to a command-and-control (C2) server, awaiting instructions to exfiltrate credentials and deploy additional plugins. Supported commands include system metadata collection, shell command execution, web browser data exfiltration, and Phone Link recon log extraction.

The Pheno plugin conducts reconnaissance on the Phone Link application, writing the data to a staging folder. CloudZ then retrieves this data and transmits it to the C2 server. This highlights the advanced capabilities of CloudZ and its plugins, posing significant threats to affected systems.

The use of CloudZ RAT and its Pheno plugin underscores the evolving nature of cyber threats, where legitimate software functionalities are exploited to bypass security measures. This attack serves as a reminder of the importance of robust security protocols and continuous monitoring to mitigate such risks in modern computing environments.

The Hacker News Tags:CloudZ RAT, credential theft, Cyberattack, Cybersecurity, endpoint security, Malware, Microsoft, mobile data, Phone Link, SMS interception, threat intelligence, two-factor authentication

Post navigation

Previous Post: Phantom Device Exploits Bypass Azure AD Security
Next Post: CISA Urges Critical Infrastructure to Enhance Cybersecurity

Related Posts

Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider The Hacker News
Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice The Hacker News
CTEM’s Core: Prioritization and Validation CTEM’s Core: Prioritization and Validation The Hacker News
Optimizing SOC with AI and Human Expertise Optimizing SOC with AI and Human Expertise The Hacker News
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors The Hacker News
New Fast16 Malware Uncovered: Cybersecurity Concerns Rise New Fast16 Malware Uncovered: Cybersecurity Concerns Rise The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OWASP Unveils Subtractive Security Top 10 for Cyber Defense
  • Key Cybersecurity Announcements at Black Hat USA 2026
  • DarkSword iOS Exploit Impacts 180 Websites and 27 Servers
  • CISO Insights: Russ Kirby on Passion and Leadership
  • Cyber Attacks Leverage Fake Software Updates for Remote Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OWASP Unveils Subtractive Security Top 10 for Cyber Defense
  • Key Cybersecurity Announcements at Black Hat USA 2026
  • DarkSword iOS Exploit Impacts 180 Websites and 27 Servers
  • CISO Insights: Russ Kirby on Passion and Leadership
  • Cyber Attacks Leverage Fake Software Updates for Remote Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark