CloudZ RAT Abuses Microsoft Phone Link SMS Interception | MSSP Advisory

Critical
DateMay 5, 2026
📋Executive Summary
The CloudZ remote access trojan with its Pheno plugin exploits Microsoft Phone Link to intercept SMS-based one-time passwords from Windows systems without touching the mobile device. The attack monitors data mirrored through Phone Link, scanning for active processes to steal authentication codes and credentials synced from smartphones. Cisco Talos identified this campaign targeting enterprise environments in January 2026.
⚠️Why It Matters for MSSPs
Your RMM agents and technician workstations running Phone Link become SMS interception points that bypass mobile device security entirely. Every client using Phone Link for SMS OTPs on domain-joined machines creates a credential theft vector that traditional mobile device management cannot detect or prevent.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Identity Access

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.