[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhZ2r5VDCfz_OtNuw2I2I8RhsOLuXAY1fm57UNT1ZJUw":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":32},"0f1600d6-f527-4ccf-aca4-c960b0a4cf49","Attacks Abuse Windows Phone Link to Steal Texts &amp; Bypass 2FA","attacks-abuse-windows-phone-link-to-steal-texts-amp-bypass-2fa-d204cc","In hard-to-detect attacks, hackers are dropping the CloudZ RAT and a fresh plugin, Pheno, to hijack the Windows-based bridge between PCs and smartphones.","Attackers are leveraging the Windows Phone Link application—a legitimate Windows-based bridge connecting PCs to Android smartphones—to deploy the CloudZ RAT malware and a new plugin called Pheno. The attack chain allows adversaries to intercept SMS messages and bypass two-factor authentication mechanisms. These attacks are difficult to detect due to the legitimate nature of the Phone Link application.","CloudZ RAT and Pheno plugin exploited via Windows Phone Link to steal texts and bypass 2FA.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fattacks-abuse-windows-phone-link-texts-bypass-2fa","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt1e09d5a76fa90123\u002F69fb1b614f86c9e600c8fbcf\u002Fsmartphone_warning_Mohd_Izzuan_Roslan_Alamy.png?width=1280&auto=webp&quality=80&disable=upscale","2026-05-06T10:30:27+00:00","2026-05-06T16:00:20.72231+00:00",8,[18,21,23,25],{"name":19,"type":20},"Windows Phone Link","product",{"name":22,"type":20},"CloudZ RAT",{"name":24,"type":20},"Pheno",{"name":26,"type":27},"Microsoft","vendor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":28,"icon":11,"name":30,"slug":31},"Malware","malware",[33,38,43],{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":39},{"id":40,"icon":11,"name":41,"slug":42},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":44},{"id":45,"icon":11,"name":46,"slug":47},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[49,51],{"type":31,"value":22,"context":50},"Remote access trojan deployed via Windows Phone Link to steal SMS and bypass 2FA",{"type":31,"value":24,"context":52},"Plugin used with CloudZ RAT to enhance SMS interception and 2FA bypass capabilities"]