Desktop Phone Link Becomes an OTP Theft Bridge

A Windows desktop that runs Phone Link can become a credential trap. CloudZ RAT’s new Pheno plugin abuses the PC-to-phone bridge to pull SMS and OTP data from the local Phone Link database, so patching the phone does not stop the theft path. Cisco Talos says the intrusion has been active since at least January 2026. The plugin watches for active Phone Link sessions and can intercept SMS-based OTPs and authenticator notifications without malware on the mobile device, which makes the desktop the weak point in the MFA chain. The risk persists anywhere Phone Link is enabled on a compromised Windows 10 or 11 system. Once the attacker owns the PC, the phone no longer needs to be infected for mobile codes and notifications to be exposed.

Part of the PlainSec briefing for 2026-05-05

Sources