Cloudz Malware Abuses Microsoft Phone Link to Steal SMS and OTPs
The Threat
A new malware variant called Cloudz has been discovered abusing Microsoft Phone Link to steal SMS messages and one-time passwords (OTPs) from connected devices. This represents a growing threat vector as more users connect their phones to their computers.
How It Works
The Cloudz malware targets Microsoft Phone Link, the application that syncs Android phones with Windows PCs. By compromising Phone Link, the malware can intercept SMS messages containing two-factor authentication codes, password reset links, and other sensitive information.
Why This Is Dangerous
OTP interception undermines one of the most common security controls. If attackers can intercept SMS-based 2FA codes, they can bypass account security measures that users rely on to protect their accounts.
Protection Measures
- Keep Microsoft Phone Link and Windows updated to the latest versions
- Use authenticator apps instead of SMS for 2FA where possible
- Monitor connected devices and remove any unauthorized connections
- Be cautious about installing software from untrusted sources
The Broader Trend
As devices become more interconnected, the attack surface expands. Security-conscious users and organizations need to be aware of the risks introduced by device synchronization and take appropriate protective measures.