Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CloudZ RAT potentially steals OTP messages using Pheno plugin

0
Medium
Vulnerabilityremote
Published: 05/05/2026 (05/05/2026, 10:00:18 UTC)
Source: Cisco Talos

Description

Cisco Talos identified an intrusion active since at least January 2026 involving the CloudZ remote access tool (RAT) combined with a previously undocumented plugin named 'Pheno'. The Pheno plugin is reported to potentially steal one-time password (OTP) messages, indicating targeted information theft capabilities. No specific affected software versions or patches are currently documented. There is no evidence of known exploits in the wild beyond this discovery. The threat is assessed as medium severity based on the available information.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 20:29:02 UTC

Technical Analysis

Cisco Talos discovered an ongoing intrusion campaign where an unknown attacker deployed the CloudZ RAT alongside a novel plugin called 'Pheno'. This plugin is designed to steal OTP messages, which could facilitate unauthorized access to accounts protected by multi-factor authentication. The campaign has been active since at least January 2026. No affected product versions or patches have been identified, and the CloudZ RAT is not a cloud service. The technical details are documented in a Cisco Talos blog post dated May 2026.

Potential Impact

The primary impact is the potential theft of OTP messages, which could undermine multi-factor authentication security and enable attackers to bypass additional authentication layers. This could lead to unauthorized access to sensitive accounts or systems where OTPs are used. There is no indication of broader system compromise or other payloads beyond the RAT and Pheno plugin from the provided data.

Mitigation Recommendations

No patch or official remediation is currently documented for this threat. Organizations should monitor Cisco Talos advisories for updates. Given the nature of the threat, reviewing and enhancing OTP delivery security and monitoring for unusual RAT activity may be prudent. However, no vendor advisory or patch information is available to confirm specific remediation steps at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://blog.talosintelligence.com/cloudz-pheno-infostealer/","fetched":true,"fetchedAt":"2026-05-26T20:27:41.354Z","wordCount":2358}

Threat ID: 6a16023fe29bf47b505cefea

Added to database: 05/26/2026, 20:27:43 UTC

Last enriched: 05/26/2026, 20:29:02 UTC

Last updated: 07/30/2026, 14:39:44 UTC

Views: 52

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses