Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CloudZ Malware Exploits Phone Link for Credential Theft

CloudZ Malware Exploits Phone Link for Credential Theft

Posted on May 6, 2026 By CWS

Cybersecurity experts have revealed a sophisticated cyberattack leveraging the CloudZ remote access tool (RAT) and an undocumented plugin named Pheno to facilitate credential theft. Researchers from Cisco Talos, Alex Karkins and Chetan Raghuprasad, have shed light on this intrusion aimed at stealing credentials and potentially intercepting one-time passwords (OTPs).

Novel Attack Vector Exploits Phone Link

This innovative attack exploits CloudZ’s custom Pheno plugin to hijack the communication bridge between PCs and phones by misusing Microsoft’s Phone Link application. The plugin can monitor active Phone Link processes, potentially intercepting sensitive data such as SMS and OTPs without needing to infect the phone itself. This strategy highlights the risks associated with cross-device syncing features, which can inadvertently open pathways for credential theft and bypass two-factor authentication.

Importantly, the attack does not require compromising the mobile device directly, showcasing how legitimate features can be manipulated for malicious purposes. This malware campaign has reportedly been active since January 2026, although it has not been attributed to any specific threat group.

Technical Details of the Attack Chain

Phone Link, integrated into Windows 10 and 11, enables users to connect their computers with Android or iOS devices via Wi-Fi and Bluetooth, facilitating calls and messages. Threat actors have been observed attempting to exploit this application using CloudZ RAT and Pheno by confirming Phone Link activity on victim systems and accessing the SQLite database used for storing synchronized data.

The attack begins with an unidentified initial access method, allowing the deployment of a fake ConnectWise ScreenConnect executable. This executable downloads and executes a .NET loader, incorporating a PowerShell script to establish persistence through a scheduled task. The intermediate loader conducts hardware and environment checks to avoid detection before deploying the modular CloudZ trojan.

Functionality and Impact of CloudZ RAT

Once active, the .NET-compiled trojan decrypts its configuration and connects to a command-and-control (C2) server, awaiting instructions to exfiltrate credentials and deploy additional plugins. Supported commands include system metadata collection, shell command execution, web browser data exfiltration, and Phone Link recon log extraction.

The Pheno plugin conducts reconnaissance on the Phone Link application, writing the data to a staging folder. CloudZ then retrieves this data and transmits it to the C2 server. This highlights the advanced capabilities of CloudZ and its plugins, posing significant threats to affected systems.

The use of CloudZ RAT and its Pheno plugin underscores the evolving nature of cyber threats, where legitimate software functionalities are exploited to bypass security measures. This attack serves as a reminder of the importance of robust security protocols and continuous monitoring to mitigate such risks in modern computing environments.

The Hacker News Tags:CloudZ RAT, credential theft, Cyberattack, Cybersecurity, endpoint security, Malware, Microsoft, mobile data, Phone Link, SMS interception, threat intelligence, two-factor authentication

Post navigation

Previous Post: Phantom Device Exploits Bypass Azure AD Security
Next Post: CISA Urges Critical Infrastructure to Enhance Cybersecurity

Related Posts

Infostealer Targets OpenClaw AI, Exposes Security Flaws Infostealer Targets OpenClaw AI, Exposes Security Flaws The Hacker News
Severe Vulnerability Exploited in Flowise AI Platform Severe Vulnerability Exploited in Flowise AI Platform The Hacker News
Echo Chamber Jailbreak Tricks LLMs Like OpenAI and Google into Generating Harmful Content Echo Chamber Jailbreak Tricks LLMs Like OpenAI and Google into Generating Harmful Content The Hacker News
Access Control: The New Challenge of Shadow AI Access Control: The New Challenge of Shadow AI The Hacker News
Europol Dismantles Major Phishing Service Linked to 64,000 Attacks Europol Dismantles Major Phishing Service Linked to 64,000 Attacks The Hacker News
Rokarolla Malware Targets Banking Apps with Advanced Tactics Rokarolla Malware Targets Banking Apps with Advanced Tactics The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys
  • AutoJack Exploit Risks AI Agents with Code Execution
  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys
  • AutoJack Exploit Risks AI Agents with Code Execution
  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark