Experts warn of ‘unknown threat’ exploiting Microsoft Phone Link tool to steal SMS and OTP information


  • A new CloudZ plugin, Phenohijacks Microsoft Phone Link to steal SMS and OTPs from connected Android devices
  • This allows attackers to bypass 2FA without compromising the phone itself.
  • The RAT retains all of its remote access capabilities, with researchers advocating abandoning SMS authentication.

A new version of the CloudZ Remote Access Trojan (RAT) for Windows now comes with a new plugin that steals data from a connected Android device, experts have revealed.

Cisco Talos security researchers recently spotted the upgraded variant while investigating a breach that has been ongoing since January 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top