Pheno is a previously undocumented malicious plugin/module used with the CloudZ .NET remote access trojan in a Windows-focused campaign reported by Cisco Talos and active since at least January 2026. Its role is to abuse Microsoft Phone Link (formerly Your Phone) on compromised Windows 10 and Windows 11 systems to identify active PC-to-phone bridge sessions and enable theft of data synchronized from paired smartphones without directly infecting the phones.
Pheno scans running processes for Phone Link-related keywords including "YourPhone," "PhoneExperienceHost," and "Link to Windows." It records matching process IDs and file paths to staging files, including phonelink-[COMPUTERNAME].txt, in locations such as C:\programdata\Microsoft\feedback\cm and %TEMP%\Microsoft\feedback\cm. It then searches the staged output for the string "proxy" to determine whether Phone Link is actively routing traffic between the PC and the paired phone; when this condition is met, it writes "Maybe connected" to its output. Talos reported that CloudZ reads this staging data and exfiltrates it to command and control.
The plugin specifically targets Phone Link artifacts on the Windows host, including local SQLite databases such as PhoneExperiences-*.db, which store synchronized SMS messages, call logs, notifications, and potentially authenticator notifications. This can expose credentials, SMS messages, one-time passwords, and other authentication codes delivered to the victim's mobile device, creating a path to two-factor authentication bypass via the compromised Windows endpoint.
In observed intrusions, Pheno was dropped by CloudZ after an infection chain involving a fake ScreenConnect update, a Rust-based loader, and a .NET loader executed via regasm.exe with persistence through a scheduled task running as SYSTEM. Reported associated indicators include the filename pheno.exe, observed in C:\Windows\TEMP, and attacker infrastructure used by the broader CloudZ operation, including Cloudflare Workers and Pastebin-hosted secondary configuration. Talos stated the threat actor was unknown and published indicators of compromise, ClamAV signatures, and Snort rules for detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices.
the attacker using the CloudZ RAT can potentially intercept the Phone Link application’s SQLite database file ... potentially compromising SMS-based OTP messages and other authenticator application notification messages
With confirmed Phone Link activity on the victim's machine, the attacker using the CloudZ RAT can potentially intercept the Phone Link application’s SQLite database file… potentially compromising SMS-based OTP messages and other authenticator application notification messages.
The Pheno plugin continuously scans running processes for keywords associated with Phone Link, such as YourPhone, PhoneExperienceHost and Link to Windows.
Synchronized data is written to local SQLite database files on the PC, including one named PhoneExperiences-*.db. Cisco Talos said this design allowed attackers to capture mobile content from the endpoint without ever touching the phone.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented custom plugin used with CloudZ to identify active Microsoft Phone Link processes, confirm whether the PC-phone proxy connection is active, and enable theft of synchronized mobile data such as SMS messages and OTPs from the Phone Link SQLite database.
A previously undocumented CloudZ plugin that scans for Microsoft Phone Link-related processes, checks for signs of an active local relay session, flags systems likely connected to a phone, and enables collection of synced SMS messages and one-time passwords from Windows hosts.
A CloudZ RAT plugin that targets Windows Phone Link by detecting synced mobile-device bridge processes, identifying proxy connections, and accessing Phone Link-related data stores to capture notifications, SMS, call history, and potentially one-time passwords.
A newly observed malware plugin used with CloudZ to detect active Microsoft Phone Link sessions by monitoring processes such as YourPhone and PhoneExperienceHost, enabling potential interception of SMS messages and OTP-related notifications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.