CloudZ Malware Abuses Phone Link to Steal SMS OTPs

2026-05-06T20:52:25Zeae6ae453cda957e1a44309edccd582d3fe2210d9156d6bcfec3a23ab962d84c
browser-extensions-datachaos-ransomwarecisacloudzcompromised-credentialscursor-extension-flawfalse-flaginfostealerslinux-kernel-zero-daymass-phishingmicrosoft-phone-linknCSC-patch-wave-recommendationnpm-malwarephenophishingratsigned-rmmsms-otp-theftsupply-chaintrellix-breachtrojanized-softwarevect-ransomwarevenomous-helperwiperzero-trust

What happened

Multiple high-impact security stories: Cisco Talos uncovered the CloudZ RAT with a Pheno plugin abusing Microsoft Phone Link to intercept SMS one‑time passwords. Microsoft warned of a mass phishing campaign using fake compliance emails targeting ~35,000 users. Other notable incidents include Rapid7’s discovery of an Iran‑linked APT conducting a Chaos ransomware false‑flag, Venomous#Helper phishing deploying signed RMM for persistent access, a trojanized supply‑chain compromise of a Yanbian gaming platform (Windows/Android), and a malicious npm dependency that spreads like a worm and targets or

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
eae6ae453cda957e1a44309edccd582d3fe2210d9156d6bcfec3a23ab962d84c
Enrichment time
2026-05-06T20:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CloudZ Malware Abuses Phone Link to Steal SMS OTPs · Baitaphish