CloudZ Malware Abuses Phone Link to Steal SMS OTPs
2026-05-06T20:52:25Z•eae6ae453cda957e1a44309edccd582d3fe2210d9156d6bcfec3a23ab962d84c
browser-extensions-datachaos-ransomwarecisacloudzcompromised-credentialscursor-extension-flawfalse-flaginfostealerslinux-kernel-zero-daymass-phishingmicrosoft-phone-linknCSC-patch-wave-recommendationnpm-malwarephenophishingratsigned-rmmsms-otp-theftsupply-chaintrellix-breachtrojanized-softwarevect-ransomwarevenomous-helperwiperzero-trust
What happened
Multiple high-impact security stories: Cisco Talos uncovered the CloudZ RAT with a Pheno plugin abusing Microsoft Phone Link to intercept SMS one‑time passwords. Microsoft warned of a mass phishing campaign using fake compliance emails targeting ~35,000 users. Other notable incidents include Rapid7’s discovery of an Iran‑linked APT conducting a Chaos ransomware false‑flag, Venomous#Helper phishing deploying signed RMM for persistent access, a trojanized supply‑chain compromise of a Yanbian gaming platform (Windows/Android), and a malicious npm dependency that spreads like a worm and targets or
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- eae6ae453cda957e1a44309edccd582d3fe2210d9156d6bcfec3a23ab962d84c
- Enrichment time
- 2026-05-06T20:52:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.