0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Cisco Talos Reports CloudZ Malware Exploiting Microsoft Phone Link to Intercept SMS OTPs (infosecurity-magazine.com)

· 82d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • CloudZ RAT and Pheno plugin abuse Microsoft Phone Link
  • Interception of SMS one-time passwords
  • Bypasses two-factor authentication

"Cisco Talos has identified a new malware campaign using CloudZ RAT and its Pheno plugin to intercept SMS one-time passwords via Microsoft's Phone Link application. The malware targets Android devices and Windows systems, enabling attackers to bypass two-factor authentication. This technique allows threat actors to gain unauthorized access to sensitive accounts, including banking and email. The use of a legitimate remote access tool (Phone Link) for malicious purposes underscores the evolving sophistication of modern cyber threats. Organizations are advised to monitor for suspicious Phone Link activity and enforce additional authentication layers."

Discussion Matrix

0 segments

no comments yet.