Experts warn Microsoft Phone Link tool exploited by ‘unknown threat’ to steal SMS and OTP details


  • A new CloudZ plugin, Phenohijacks Microsoft Phone Link to steal SMS and OTPs from connected Android devices
  • This allows attackers to bypass 2FA without compromising the phone itself
  • RAT retains full remote access, with researchers calling for a shift away from SMS-based authentication

A new version of the CloudZ remote access trojan (RAT) for Windows now comes with a new plugin that steals data from a connected Android device, experts have revealed.

Security researchers Cisco Talos recently discovered the upgraded variant while investigating a breach that has been ongoing since January 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top