Executive Summary
A newly observed cyber intrusion campaign is leveraging a Remote Access Trojan (RAT) known as CloudZ to bypass multi-factor authentication controls by stealing credentials and one-time passwords (OTPs).
Unlike traditional mobile malware, this attack does not compromise the victim’s smartphone directly. Instead, it abuses Microsoft’s legitimate Windows Phone Link feature, turning a trusted productivity tool into a credential interception channel.
This development represents a significant evolution in attacker tactics like security controls protecting mobile devices remaining intact while authentication data is silently harvested from the Windows endpoint.
The campaign has reportedly been active since January 2026 and focuses on credential theft, account takeover, and persistence within enterprise environments.
What is CloudZ RAT?
CloudZ is a modular Remote Access Trojan designed to provide attackers with remote control over compromised Windows systems. Once deployed, it enables threat actors to:
- Steal stored browser credentials
- Execute commands remotely
- Maintain persistent access
- Deploy additional malicious plugins
In this campaign, attackers enhanced CloudZ with a previously undocumented plugin called Pheno, specifically engineered to harvest authentication data synced from mobile devices.
How the Attack Works
1. Initial Compromise
Victims are tricked into installing malware disguised as legitimate software updates (including fake remote support or update installers).
Once executed, CloudZ RAT installs silently on the Windows device.
2. Abuse of Windows Phone Link
Microsoft Phone Link (formerly Your Phone) allows users to:
- Read SMS messages on their PC
- View notifications
- Make calls and access synced phone data
The malware does not infect the mobile device.
Instead, it monitors the Windows system for active Phone Link sessions.
3. Pheno Plugin Activation
The Pheno module continuously scans for Phone Link processes such as:
- PhoneExperienceHost
- YourPhone
- Link to Windows
When a connection between phone and PC is detected, the malware flags the system for data harvesting.
4. OTP and Credential Theft
Phone Link stores synchronized mobile data locally in database files on the Windows machine.
CloudZ extracts information directly from these files, including:
- SMS messages
- Authentication notifications
- One-time passwords (OTPs)
- Potential authenticator codes
This allows attackers to intercept login verification codes without touching the phone itself.
Why This Technique Is Dangerous
- It bypasses traditional security assumptions
- Invisible to Mobile Security Controls
- Enables Full Account Takeover
Why This Attack Matters
Most organizations rely on Multi-Factor Authentication as a primary defense against credential compromise.
This campaign undermines that assumption.
Instead of attacking the phone where OTPs are generated, attackers exploit the trusted bridge between phone and computer.
Indicators of Suspicious Activity
Security teams should monitor for:
- Unexpected installation of remote access tools or update installers
- Abnormal access to Phone Link database files
- Unknown processes accessing SMS synchronization data
- Windows systems repeatedly querying Phone Link services
- Login events succeeding immediately after OTP generation
Recommended Mitigation Actions
- Restrict or review use of Microsoft Phone Link in corporate environments.
- Validate all remote support or software update installations.
- Enforce endpoint detection monitoring on Windows systems interacting with mobile devices.
- Reset credentials for users suspected of compromise.
Security governance should therefore expand from device protection to data-flow protection across connected ecosystems.



.jpeg)

.jpeg)

.png)

.png)
.png)