WelcomeUser Guide
ToSPrivacyCanary
DonateBugsLicense

©2026 Poal.co

634

Archive: https://archive.today/5uIAM

From the post:

>A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices. The malware was discovered in an intrusion that was active since at least January and researchers believe the threat actor's purpose was to steal credentials and temporary passcodes. Microsoft Phone Link comes installed on Windows 10 and 11, and allows using the computer to make and take calls, respond to texts, or view notifications received on the mobile device (Android and iOS).

Archive: https://archive.today/5uIAM From the post: >>A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices. The malware was discovered in an intrusion that was active since at least January and researchers believe the threat actor's purpose was to steal credentials and temporary passcodes. Microsoft Phone Link comes installed on Windows 10 and 11, and allows using the computer to make and take calls, respond to texts, or view notifications received on the mobile device (Android and iOS).
[–] 1 pt

It’s partly stupidity, but the main reason is online services want to identify their users, and they want to prevent users from making thousands of accounts to abuse their services. I understand the latter, but there is a better way than forcing people to use a non secure, faulty auth method.