New CloudZ Malware Exploits Microsoft Phone Link to Steal Sensitive Information
A sophisticated malware known as CloudZ has emerged, utilizing a new plugin called Pheno to hijack Microsoft Phone Link connections. This attack, active since January, targets users of Windows 10 and 11, allowing cybercriminals to intercept SMS messages and one-time passwords (OTPs) without compromising the victim’s mobile device.
Individuals using Microsoft Phone Link are primarily affected, as the malware can access sensitive information stored in local databases. The impact is significant, with potential exposure of credentials and security codes that could lead to unauthorized access to personal accounts.
To protect against such attacks, users are advised to avoid SMS-based OTPs and switch to more secure methods like authenticator apps that don’t rely on notifications. Employing hardware security keys is also recommended for sensitive transactions.
Risk Level: High
This attack poses a serious risk to sensitive information and user security.
Source: View Original Report
