Experts warn that Microsoft Phone Link tool is exploited by ‘unknown threat’ to steal SMS and OTP information



  • A new CloudZ plugin, phenohijacks Microsoft Phone Link to steal SMS and OTP from connected Android devices
  • This allows attackers to bypass 2FA without compromising the phone.
  • RAT retains all remote access capabilities, and researchers urge abandoning SMS-based authentication

Experts have revealed that a new version of the CloudZ Remote Access Trojan (RAT) for Windows now comes with a new add-on that steals data from a connected Android device.

Cisco Talos security researchers recently detected the improved variant while investigating a breach that has been ongoing since January 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *