Malware & Tooling · Credential Theft
Windows Malware Turns Phone Link into 2FA Bypass Phone Link turns a compromised Windows PC into a credential trap. If the desktop is owned, attackers can pull mirrored SMS and OTPs from local sync data without touching the phone, so the usual "protect the handset " model misses the real trust boundary.
Cisco Talos says CloudZ RAT and the Pheno plugin have been abusing Microsoft Phone Link on Windows 10 and 11 since at least January 2026. The tools look for active Phone Link sessions, then access the local SQLite database that stores synchronized mobile data, including SMS and one-time passwords.
That makes any Windows endpoint with Phone Link enabled a potential 2FA bypass point. The phone can stay clean and the OTP can still be stolen from the PC side, which leaves SMS-based authentication exposed as long as desktop sync remains in place.
5 sources · May 6
Timeline Sources May 6 Infosecurity Magazine
CloudZ Malware Abuses Phone Link to Steal SMS OTPs
Cisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPs
original May 6 Dark Reading
Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA
Attackers are dropping the CloudZ RAT and a fresh plug-in, Pheno, to hijack the Windows-based bridge between PCs and smartphones.
original May 6 The Hacker News
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
CloudZ RAT exploits Phone Link since Jan 2026, stealing credentials and OTPs via Pheno plugin, bypassing 2FA protections.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-05-05
Every edition of this story: Windows Malware Turns Phone Link into 2FA Bypass
Malware & Tooling · Credential Theft
Windows Malware Turns Phone Link into 2FA Bypass Phone Link turns a compromised Windows PC into a credential trap. If the desktop is owned, attackers can pull mirrored SMS and OTPs from local sync data without touching the phone, so the usual "protect the handset " model misses the real trust boundary.
Cisco Talos says CloudZ RAT and the Pheno plugin have been abusing Microsoft Phone Link on Windows 10 and 11 since at least January 2026. The tools look for active Phone Link sessions, then access the local SQLite database that stores synchronized mobile data, including SMS and one-time passwords.
That makes any Windows endpoint with Phone Link enabled a potential 2FA bypass point. The phone can stay clean and the OTP can still be stolen from the PC side, which leaves SMS-based authentication exposed as long as desktop sync remains in place.
5 sources · May 6
Timeline Sources May 6 Infosecurity Magazine
CloudZ Malware Abuses Phone Link to Steal SMS OTPs
Cisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPs
original May 6 Dark Reading
Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA
Attackers are dropping the CloudZ RAT and a fresh plug-in, Pheno, to hijack the Windows-based bridge between PCs and smartphones.
original May 6 The Hacker News
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
CloudZ RAT exploits Phone Link since Jan 2026, stealing credentials and OTPs via Pheno plugin, bypassing 2FA protections.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-05-05
Every edition of this story: Windows Malware Turns Phone Link into 2FA Bypass