Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A newly identified remote access trojan called CloudZ exploits the legitimate Windows Phone Link application to silently harvest one-time passwords synced from paired Android devices, bypassing SMS-based two-factor authentication without touching the mobile device. Organizations using Windows 10 or 11 with Phone Link enabled are exposed to credential theft that most endpoint detection tools will not catch. The business risk is account takeover across any system protected by SMS-based MFA, including email, banking portals, VPNs, and enterprise SaaS platforms.

Author

Tech Jacks Solutions