CloudZ RAT Pheno Plugin SMS OTP Theft | MSSP Advisory

Critical
DateMay 5, 2026
📋Executive Summary
CloudZ RAT now includes a plugin called Pheno that hijacks Microsoft Phone Link connections to intercept SMS messages and one-time passwords from mobile devices. The malware establishes persistent access through Phone Link's legitimate connection between Windows PCs and mobile phones, bypassing traditional SMS-based multi-factor authentication. This targets the Phone Link service that many users enable for productivity features.
⚠️Why It Matters for MSSPs
Your clients running Phone Link become vulnerable to MFA bypass attacks that defeat SMS-based two-factor authentication across all their business accounts. Phone Link runs on millions of Windows systems and creates a direct pathway from compromised PCs to mobile SMS traffic. Any client breach involving MFA bypass will raise questions about your security guidance on Microsoft productivity features.
Recommended Action
Audit all client environments for active Microsoft Phone Link installations and disable the service through Group Policy or direct configuration where business justification does not exist.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Identity Access

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.