Cisco Talos reported an active intrusion in which an unknown threat actor deployed the CloudZ remote access trojan alongside a previously undocumented plugin called Pheno to steal credentials and potentially capture one-time passwords. The campaign has been active since at least January 2026 and appears to rely on a fake ScreenConnect update, a Rust-based dropper, and a .NET loader that establishes persistence through a scheduled task while abusing regasm.exe as a living-off-the-land binary. Talos said the initial access vector remains unknown, but the malware used layered anti-analysis techniques, decrypted configuration data in memory, and fetched additional configuration from attacker-controlled infrastructure including Cloudflare Workers and Pastebin before communicating with a command-and-control server at 185.196.10.136:8089.
The newly identified Pheno plugin was designed to abuse Microsoft Phone Link, which mirrors mobile notifications and SMS content to Windows devices, allowing the attackers to target data without compromising the victim’s phone directly. Talos found that Pheno monitored for active Phone Link processes, checked for signs of an active proxy relay, and wrote reconnaissance results to staging folders for exfiltration by CloudZ. Researchers assessed that this workflow could expose Phone Link SQLite database content including SMS messages, authenticator notifications, and other OTP-related data, giving attackers a path to bypass or weaken multi-factor authentication protections during credential theft operations.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
On publication, Cisco Talos publicly documented the campaign’s tooling and tradecraft, including CloudZ’s anti-analysis features, use of regasm.exe and scheduled tasks for persistence, and retrieval of configuration data from attacker-controlled infrastructure. Talos assessed that the Pheno plugin could abuse Microsoft Phone Link to access mirrored SMS messages, authenticator notifications, and one-time-password-related content from the victim’s Windows system.
Cisco Talos reported that an intrusion involving the CloudZ remote access trojan and a previously undocumented plugin called Pheno had been active since at least January 2026. The attacker used an unknown initial access vector, followed by a fake ScreenConnect update, a Rust-based dropper, and a .NET loader to establish persistence and deploy the malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcedarkwebinformer.com
Open sourcezdnet.com
Open sourcebleepingcomputer.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.