CloudZ is a modular .NET remote access trojan (RAT) observed by Cisco Talos in an intrusion campaign active since at least January 2026. It was deployed on compromised Windows systems together with a previously undocumented plugin, Pheno, to abuse Microsoft Phone Link and harvest credentials, synchronized SMS messages, one-time passwords, and authenticator-related notifications from paired smartphones without directly infecting the phones. Phone Link artifacts targeted by the operation include local SQLite databases such as PhoneExperiences-*.db, which store synchronized messages, call logs, and notifications on Windows 10 and Windows 11 hosts.
The observed infection chain began with a fake ScreenConnect update. Talos reported the initial access vector was unknown. A Rust-compiled dropper using filenames such as systemupdates.exe and Windows-interactive-update.exe dropped a .NET loader disguised as update.txt or msupdate.txt, and the payload was executed via the legitimate regasm.exe binary. Persistence was established through a scheduled task named SystemWindowsApis under \Microsoft\Windows\ running at startup under the SYSTEM account. CloudZ was described as obfuscated with ConfuserEx and using anti-analysis and anti-reverse-engineering measures including timing-based sleep checks, enumeration of tools such as Wireshark, Fiddler, Procmon, and Sysmon, and checks for virtual machine or sandbox indicators.
CloudZ decrypts embedded configuration, establishes encrypted command-and-control communications, and retrieves secondary configuration from attacker-controlled infrastructure including Cloudflare Workers and Pastebin pages associated with the handle HELLOHIALL. Reported infrastructure includes 185.196.10.136:8089, hxxps://round-cherry-4418[.]hellohiall[.]workers[.]dev, and https://pastebin[.]com/raw/8pYAgF0Z. Talos also observed download of the Pheno plugin from hxxps://orange-cell-1353[.]hellohiall[.]workers[.]dev/pheno.exe to C:\Windows\TEMP\pheno.exe. CloudZ rotates among hardcoded browser-like user-agent strings and uses anti-caching HTTP headers to blend traffic. A Talos Snort rule also detects HTTP requests matching CloudZ C2 message patterns.
Documented CloudZ capabilities include credential and browser data theft, host profiling, arbitrary command execution, file deletion, download and write operations, plugin loading and management, and screen recording. Pheno performs reconnaissance for active Phone Link sessions by scanning running processes for strings such as YourPhone, PhoneExperienceHost, and Link to Windows, writing results to staging files such as phonelink-<COMPUTERNAME>.txt, and checking for the string "proxy" to infer an active relay session. When connectivity is confirmed, it marks the host as "Maybe connected," enabling CloudZ to target Phone Link data for exfiltration. Cisco Talos did not attribute the campaign to a known threat actor and described the operator as unknown. Published indicators include filenames systemupdates.exe, Windows-interactive-update.exe, pheno.exe, the scheduled task name SystemWindowsApis, the C2 IP 185[.]196[.]10[.]136:8089, and the Workers/Pastebin URLs noted above.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The latter was scheduled to run at system startup under the SYSTEM account.
The Rust-compiled dropper installs a scheduled task named “SystemWindowsApis” that runs at system startup under the SYSTEM account, ensuring the malware restarts after every reboot.
CloudZ itself is a .NET executable obfuscated with ConfuserEx and compiled in mid-January 2026.
It also generates its most sensitive functions on the fly in memory, making them harder to catch or reverse-engineer.
The observed infection chain began with the execution of a fake ScreenConnect update... A Rust-compiled loader, using filenames such as systemupdates.exe, dropped a .NET loader disguised as a text file.
It uses the legitimate Windows utility regasm.exe as a living-off-the-land binary to execute the payload, helping it blend in with normal system activity.
A Rust-compiled loader, using filenames such as systemupdates.exe, dropped a .NET loader disguised as a text file, which then deployed CloudZ via the legitimate regasm.exe binary.
According to Talos and BleepingComputer, it supports browser data theft...
From that point, the attacker has a full toolkit to explore the victim’s machine, steal browser data, and activate the Pheno plugin.
With confirmed Phone Link activity on the victim's machine, the attacker using the CloudZ RAT can potentially intercept the Phone Link application’s SQLite database file… potentially compromising SMS-based OTP messages and other authenticator application notification messages.
Once deployed, it scans all running processes for keywords tied to the Phone Link application, including “YourPhone,” “PhoneExperienceHost,” and “Link to Windows.”
According to Talos and BleepingComputer, it supports browser data theft, host system profiling...
With a confirmed Phone Link connection, the operator can then go after the SQLite database file (PhoneExperiences-*.db) where Phone Link locally caches synchronized SMS and notifications...
Talos observed multiple anti-analysis layers, including timing-based sleep checks... and searches for virtual machine indicators in the system path and hostname.
This rule looks for an HTTP request conforming to the pattern of CloudZ C2 messages.
The RAT pulls secondary configuration from attacker-controlled staging servers and Pastebin pages, rotates through three hardcoded user-agent strings to blend HTTP traffic with legitimate browser activity.
The RAT pulls secondary configuration from attacker-controlled staging servers and Pastebin pages... and supports commands ranging from credential exfiltration to plugin loading and screen recording.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan deployed via a fake ScreenConnect update and a .NET loader. It provides attackers with remote access to victim machines, steals browser data and login credentials, evades analysis, persists via a scheduled task and regasm.exe, and abuses Microsoft Phone Link through the Pheno plugin to access synchronized SMS, call logs, notifications, and OTPs from a local SQLite database.
A .NET remote access tool used to harvest credentials, load plugins, record screens, pull secondary configuration from attacker-controlled staging servers and Pastebin, and support interception of SMS/OTP data via the Pheno plugin by abusing Microsoft Phone Link data stored on Windows endpoints.
A modular remote access trojan used on compromised Windows PCs to steal browser credentials, execute shell commands, record screens, deploy plugins, manage files, and exfiltrate Phone Link data to a C2 server.
A modular .NET-based remote access trojan that establishes persistence, performs anti-analysis checks, decrypts embedded configuration, communicates with C2 over encrypted TCP, retrieves additional configuration from Cloudflare Workers and Pastebin, and supports browser data theft, host profiling, file management, arbitrary command execution, and plugin delivery. In this campaign it is used to abuse Microsoft Phone Link and exfiltrate SMS messages, OTPs, and authenticator notifications from compromised Windows hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.