CloudZ RAT Pheno Plugin SMS OTP Theft | MSSP Advisory
Critical
DateMay 5, 2026
📋Executive Summary
CloudZ RAT now includes a plugin called Pheno that hijacks Microsoft Phone Link connections to intercept SMS messages and one-time passwords from mobile devices. The malware establishes persistent access through Phone Link's legitimate connection between Windows PCs and mobile phones, bypassing traditional SMS-based multi-factor authentication. This targets the Phone Link service that many users enable for productivity features.
⚠️Why It Matters for MSSPs
Your clients running Phone Link become vulnerable to MFA bypass attacks that defeat SMS-based two-factor authentication across all their business accounts. Phone Link runs on millions of Windows systems and creates a direct pathway from compromised PCs to mobile SMS traffic. Any client breach involving MFA bypass will raise questions about your security guidance on Microsoft productivity features.
✅Recommended Action
Audit all client environments for active Microsoft Phone Link installations and disable the service through Group Policy or direct configuration where business justification does not exist.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Identity Access
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.