
UpTrajectory Review
A new malware campaign is leveraging Microsoft's Phone Link feature to intercept SMS-based one-time passwords (OTPs) and sensitive data from Windows systems. This tactic, identified by Cisco Talos, involves a remote access trojan called CloudZ and a custom plugin named Pheno, which together allow attackers to harvest credentials and authentication codes synced from users' smartphones. This method exploits the trust relationship between mobile devices and Windows PCs, making it a significant concern for small business operators who rely on these technologies for secure communications.
For small business owners, this development underscores the importance of scrutinizing the security of integrated systems. The fact that attackers can bypass mobile device security by targeting the PC connection is alarming and highlights the need for robust endpoint protection. As cyber threats evolve, operators should consider implementing additional layers of security, such as multi-factor authentication that does not rely solely on SMS, and ensure that their systems are updated to mitigate vulnerabilities. This incident serves as a reminder that security is a shared responsibility across devices.
““According to the functionalities of the CloudZ RAT and Pheno plugin, this was with the intention of stealing victims’ credentials and potentially one-time passwords (OTPs),”” — Computerworld
Takeaway: Small business owners should enhance security measures to protect against malware exploiting device connections.
Excerpt from the original — Computerworld
A newly identified malware campaign is abusing Microsoft’s Phone Link feature to intercept SMS-based one-time passwords and other sensitive mobile data directly from Windows systems.
The activity, first observed by Cisco Talos in January 2026, involves a remote access trojan dubbed CloudZ and a custom plugin named Pheno that together allow attackers to harvest credentials and potentially capture authentication codes synced from a user’s smartphone, Talos researchers Alex Karkins and Chetan Raghuprasad wrote in a blog post.
“According to the functionalities of the CloudZ RAT and Pheno plugin, this was with the intention of stealing victims’ credentials and potentially one-time passwords (OTPs),” the researchers wrote.
The attack does not target the mobile device itself. Instead, it exploits the trust relationship between phones and Windows PCs by monitoring data mirrored through …