TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Bleeping Computer

CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs

Bill Toulas · 1 day ago · Read original ↗

ATT&CK techniques detected

3 predictions
T1566.002Spearphishing Link
45%
“cloudz malware abuses microsoft phone link to steal sms and otps a new version of the cloudz remote access tool ( rat ) is deploying a previously unseen malicious plugin called pheno that hijacks the microsoft phone link connection to steal sensitive codes from mobile devices. th…”
T1204.001Malicious Link
45%
“confirmed phone link activity on the victim ' s machine, the attacker using the cloudz rat can potentially intercept the phone link application ’ s sqlite database file on the victim ' s machine, potentially compromising sms - based otp messages and other authenticator applicatio…”
T1557.001Name Resolution Poisoning and SMB Relay
32%
“cloudz malware abuses microsoft phone link to steal sms and otps a new version of the cloudz remote access tool ( rat ) is deploying a previously unseen malicious plugin called pheno that hijacks the microsoft phone link connection to steal sensitive codes from mobile devices. th…”

Summary

A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices. [...]