Malware & Tooling · Credential Theft

Windows Malware Turns Phone Link into 2FA Bypass

Phone Link turns a compromised Windows PC into a credential trap. If the desktop is owned, attackers can pull mirrored SMS and OTPs from local sync data without touching the phone, so the usual "protect the handset" model misses the real trust boundary.

Cisco Talos says CloudZ RAT and the Pheno plugin have been abusing Microsoft Phone Link on Windows 10 and 11 since at least January 2026. The tools look for active Phone Link sessions, then access the local SQLite database that stores synchronized mobile data, including SMS and one-time passwords.

That makes any Windows endpoint with Phone Link enabled a potential 2FA bypass point. The phone can stay clean and the OTP can still be stolen from the PC side, which leaves SMS-based authentication exposed as long as desktop sync remains in place.

5 sources · May 6

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-05

Every edition of this story: Windows Malware Turns Phone Link into 2FA Bypass