Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2262 articles · 131494 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED

CloudZ RAT abuses Microsoft Phone Link to intercept OTPs

60% confidence

Description

Cisco Talos observed a CloudZ RAT with a Pheno plugin exploiting Microsoft Phone Link's SQLite database to intercept SMS-based OTPs and authenticator notifications. The malware monitors active PC-to-phone bridges established by Phone Link, accessing synchronized data without deploying malware on the mobile device.

Related News (3 articles)

Tier D
CSO Online1h ago
Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs
→ No new info (linked only)
Tier D
BleepingComputer2h ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
→ No new info (linked only)
Tier C
Cisco Talos2h ago
CloudZ RAT potentially steals OTP messages using Pheno plugin
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedMay 5, 2026
Last enriched2h ago
Tags
ratotp theftmicrosoft phone link abuse
Trending Score55
Source articles3
Independent3
Info Completeness3/14
Missing: cve_id, vendor, product, versions, cvss, epss, cwe, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
May 5, 2026
Discovered by ZDM
May 5, 2026
Actively Exploited
May 5, 2026
Exploit Available
May 5, 2026