Punto Informatico: CloudZ sfrutta Windows Phone Link per rubare codici OTP

CloudZ è un RAT che utilizza un plugin dedicato per accedere al database SQLite in cui sono salvati gli SMS ricevuti dallo smartphone collegato al PC.
The post CloudZ sfrutta Windows Phone Link per rubare codici OTP appeared first on Punto Informatico.

CloudZ exploits Windows Phone Link to steal OTP codes.

CloudZ is a RAT that uses a dedicated plugin to access the SQLite database in which SMS received by the smartphone connected to the PC are stored.
The post CloudZ exploits Windows Phone Link to steal OTP codes appeared on Punto Informatico.

#CloudZ #WindowsPhoneLink #PuntoInformatico

https://www.punto-informatico.it/cloudz-sfrutta-windows-phone-link-rubare-codici-otp/

CloudZ sfrutta Windows Phone Link per rubare codici OTP

CloudZ è un RAT che utilizza un plugin dedicato per accedere al database SQLite in cui sono salvati gli SMS ricevuti dallo smartphone collegato al PC.

Punto Informatico

📢 CloudZ RAT et plugin Pheno ciblent Microsoft Phone Link pour voler des OTP
📝 ## 🔍 Contexte

Cisco Talos a publié le 5 mai 2026 une analyse technique détaillée d'une intrusion découverte via télémétrie, active depuis au moins janvier 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-05-06-cloudz-rat-et-plugin-pheno-ciblent-microsoft-phone-link-pour-voler-des-otp/
🌐 source : https://blog.talosintelligence.com/cloudz-pheno-infostealer/
#CloudZ #ConfuserEx #Cyberveille

CloudZ RAT et plugin Pheno ciblent Microsoft Phone Link pour voler des OTP

🔍 Contexte Cisco Talos a publié le 5 mai 2026 une analyse technique détaillée d’une intrusion découverte via télémétrie, active depuis au moins janvier 2026. Un attaquant inconnu a déployé un RAT modulaire nommé CloudZ ainsi qu’un plugin inédit baptisé Pheno, dans le but de voler des identifiants et potentiellement des mots de passe à usage unique (OTP). 🎯 Vecteur d’accès initial et chaîne d’infection Le vecteur d’accès initial est inconnu. La chaîne d’infection observée est la suivante :

CyberVeille
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs

A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices.

BleepingComputer

CloudZ malware is actively abusing Microsoft Phone Link to exfiltrate SMS messages and one-time passcodes (OTPs) from Windows PCs. This isn't a Phone Link vulnerability, but a clever abuse of its design, allowing attackers to bypass 2FA by accessing mirrored phone data directly from your compromised desktop. Understand the threat and secure your endpoints.

https://www.tpp.blog/25ggtey

#cybersecurity #cloudz #microsoftphonelink

🤖 This post was AI-generated.

What is life without big clouds! #cloudz #sexy #bootycall