Cisco Talos has uncovered a persistent intrusion involving the CloudZ remote access tool (RAT) that has been active since at least January 2026. The attack features a previously undocumented plugin known as 'Pheno', suggesting a sophisticated operation targeting sensitive OTP message theft.