Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The CloudZ RAT is delivered as a .NET executable that is obfuscated using a tool called ConfuserEx.
the execution of a dropper disguised as a ScreenConnect update led to the installation and execution of a .NET loader... The .NET loader is disguised as a text file with names including “update.txt” and “msupdate.txt”
First, it attempts to use the curl utility... then finally attempts to use the Windows “bitsadmin” tool to install the plugin.
Prior to deploying CloudZ, the loader performs anti-analysis checks including a check for the elapsed time of a sleep command... It also verifies the presence of at least two processor cores and searches for the strings “virtual” and “sandbox” in the system directory path, computer name, user domain and victim username
The Pheno plugin identifies whether a mobile device is currently synced via Phone Link by scanning running process for keywords including “YourPhone, “PhoneExperienceHost” and “Link to Windows.”
Prior to deploying CloudZ, the loader performs anti-analysis checks including a check for the elapsed time of a sleep command... It also verifies the presence of at least two processor cores and searches for the strings “virtual” and “sandbox” in the system directory path, computer name, user domain and victim username
intercepting files from the SQLite database where Phone Link stores notification, SMS and call history. This could allow for the extraction of sensitive information from text messages and applications, including OTPs.
The RAT decrypts one set of embedded configuration data and retrieves secondary configuration data from external sources, including Pastebin URLs and Cloudflare Workers.
It uses three different methods to download externally hosted plugins, falling back to subsequent methods if earlier methods fail. First, it attempts to use the curl utility, then attempts to use the Invoke-WebRequest PowerShell command, then finally attempts to use the Windows “bitsadmin” tool to install the plugin.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.