Topics
Follow your own topics →
DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

CloudZ RAT potentially steals OTP messages using Pheno plugin

1 · Blog Talosintelligence · May 5, 2026, 10:20 a.m.
Threat Spotlight rat Cisco Talos Antivirus Cisco Talos DNS Security Cybersecurity remote access tools malware Intrusion Detection
Summary
Cisco Talos has uncovered a persistent intrusion involving the CloudZ remote access tool (RAT) that has been active since at least January 2026. The attack features a previously undocumented plugin known as 'Pheno', suggesting a sophisticated operation targeting sensitive OTP message theft.
Read full post on blog.talosintelligence.com →
MORE POSTS LIKE THIS
The Good, the Bad and the Ugly in Cybersecurity – Week 29
Sentinelone · Jul 17, 2026
Company Cyber
Fake GitHub repositories exploit developer trust to spread malware
Developer Tech · Jul 17, 2026
Build & Ship Cybersecurity & Development
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Blog Talosintelligence · Jul 16, 2026
Threats rat
security: ACR Stealer: Two observed intrusion chains amid increased threat activity
Sujith Quintelier · Jul 17, 2026
ACR Stealer malware
You should probably check on your smart appliances
Xe · Jul 14, 2026
Smart Appliances malware
Code Red worm, July 13, 2001
David Farquhar · Jul 13, 2026
Security Cybersecurity
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google