Malware · 131 days ago
Phone Link turns a compromised Windows PC into a credential trap. If the desktop is owned, attackers can pull mirrored SMS and OTPs from local sync data without touching the phone, so the usual "protect the handset" model misses the real trust boundary.
Cisco Talos says CloudZ RAT and the Pheno plugin have been abusing Microsoft Phone Link on Windows 10 and 11 since at least January 2026. The tools look for active Phone Link sessions, then access the local SQLite database that stores synchronized mobile data, including SMS and one-time passwords.
That makes any Windows endpoint with Phone Link enabled a potential 2FA bypass point. The phone can stay clean and the OTP can still be stolen from the PC side, which leaves SMS-based authentication exposed as long as desktop sync remains in place.
5 sources covering this story
CloudZ Malware Abuses Phone Link to Steal SMS OTPs
Cisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPs
Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA
Attackers are dropping the CloudZ RAT and a fresh plug-in, Pheno, to hijack the Windows-based bridge between PCs and smartphones.
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
CloudZ RAT exploits Phone Link since Jan 2026, stealing credentials and OTPs via Pheno plugin, bypassing 2FA protections.
CloudZ RAT potentially steals OTP messages using Pheno plugin
Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.”
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices.
Part of the PlainSec briefing for 2026-05-05