CloudZ RAT Malware Could Exploit Microsoft Phone Link App to Access Messages and OTPs, Researchers Warn

Researchers say malicious actors could gain access to notifications, messages, and OTPs synced between an infected PC and a linked phone.

Advertisement
Written by Shaurya Tomer, Edited by David Delima | Updated: 6 May 2026 17:36 IST
Highlights
  • The malicious campaign can intercept messages and OTPs
  • Researchers warn synced data is exposed on compromised Windows PCs
  • Experts urge users to update software only from verified sources

Phone Link is a mobile pairing application which comes preloaded on Windows 11

Photo Credit: Microsoft

Microsoft's Phone Link app could become a target for threat actors if a connected Windows PC is infected with malware. According to security researchers, an ongoing campaign potentially targets victims with a remote access trojan (RAT) called CloudZ. It reportedly compromises systems and can intercept sensitive information synced between smartphones and PCs when using the Phone Link app. Researchers say the attack began earlier this year and raises concerns regarding notifications, messages, and one-time passwords (OTPs) synced between the phone and the PC.

According to cybersecurity researchers at Cisco Talos, threat actors are leveraging the Microsoft Phone Link app to access synced mobile data on a compromised Windows computer. The app, notably, serves as a bridge between smartphones and PCs, allowing users to access their phone's notifications, messages, and calls directly from their computers.

Advertisement

Researchers uncovered that attackers are deploying a modular malware called CloudZ RAT, along with an additional plugin named “Pheno.” As per the blog post, the plugin specifically scans systems for active Phone Link sessions and attempts to monitor related processes such as “YourPhone,” “PhoneExperienceHost,” and “Link to Windows.”

Once an active Phone Link connection is detected, attackers can potentially intercept the app's SQLite database files, including “PhoneExperiences-*.db,” which reportedly contains synced SMS messages, call logs, and notification history. Researchers say this could expose sensitive information such as OTPs and authentication notifications synced between a phone and PC.

Advertisement

How the CloudZ RAT Phone Link Attack Works

Talos says the intrusion chain begins with victims being tricked into installing what appears to be a legitimate ScreenConnect software update. The fake installer reportedly drops a malicious Rust-based loader disguised under filenames such as “systemupdates.exe” or “Windows-interactive-update.exe.”

Once executed, the loader installs an intermediate .NET component. This is said to eventually deploy the malicious CloudZ RAT malware onto the system. It can decrypt the configuration data, connect to attacker-controlled servers, and enter a command mode that is capable of downloading plugins and stealing information.

Advertisement

In simple terms, the fake update file, when opened, quietly installs another hidden program on the PC. This program then downloads and installs the CloudZ malware. Once active, the malware connects to servers controlled by hackers and waits for instructions. It can then download extra malicious tools, monitor activity on the device, and steal sensitive information from the infected system.

Researchers also noted that CloudZ uses several evasion techniques to avoid detection, including obfuscation and anti-debugging checks. It reportedly rotates user-agent strings to disguise malicious traffic within legitimate browser activity. The malware uses multiple fallback methods, including curl, PowerShell, and bitsadmin, to download payloads.

Advertisement

What Users Should Know

Researchers have warned that since Phone Link mirrors notifications and messages between devices, an infected PC could potentially expose private conversations, authentication alerts, and OTP codes synced from a phone. According to Talos, the malware reportedly stores gathered reconnaissance data in temporary staging folders before exporting it to attacker-controlled servers.

The Pheno plugin may also reportedly check if Phone Link is actively routing traffic through a local proxy connection before attempting to monitor synced data. Researchers recommend downloading software updates only from trusted sources and keeping antivirus protection enabled on their PCs to detect any suspicious activity.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X300 FE With a 6,500mAh Battery Arrives in India at This Price
  2. Vivo X300 Ultra Debuts in India With 200-Megapixel Zeiss Cameras: See Price
  3. Vivo X300 Ultra vs Samsung Galaxy S25 Ultra vs iPhone 17 Pro Max
  4. Adobe Acrobat gets a Productivity Agent, New PDF Spaces Features
  5. Infinix Note 60 Pro Review: Just Another Mid-Ranger?
  6. Apple Agrees to Pay $250 Million Settlement for Misleading Claims on AI
  7. Samsung Galaxy A27 5G Visits Geekbench Again With Better Performance Scores
  8. CMF Watch 3 Pro With Up to 13 Days Battery Life Launched in India
  1. Samsung Galaxy A27 5G Shows Up on Geekbench Again With Slightly Improved Performance Scores
  2. Adobe Unveils New Productivity Agent for Acrobat, Adds New Features to PDF Spaces
  3. Google's May 2026 Update for Pixel Devices Rolls Out With Fixes for Slow Wireless Charging, Screen Freezing Issues
  4. Colombia Seeks to Mine Bitcoin Using Surplus Renewable Energy From Country's Coastline
  5. CloudZ RAT Malware Could Exploit Microsoft Phone Link App to Access Messages and OTPs, Researchers Warn
  6. Vaazha II: Biopic of a Billion Bros OTT Release Date: When and Where to Watch This Malayalam Drama Film Online
  7. Dacoit: A Love Story OTT Release Date: When and Where to Watch Adivi Sesh and Mrunal Thakur Starrer Online?
  8. Sony Xperia 1 VIII Price, Sale Date Reportedly Surface Online via Amazon Listing
  9. OpenAI Upgrades ChatGPT’s Default AI Model to GPT-5.5 Instant, Adds New Capabilities
  10. Oppo Reno 16 Pro Global Launch Could Follow Debut in China; BIS Listing Suggests It Will Also Come to India
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.