Related Threat Clusters
-
CloudZ RAT Exploits Microsoft Phone Link to Steal SMS OTPs
A new malware campaign involving the CloudZ remote access trojan (RAT) and its Pheno plugin is targeting Microsoft’s Phone Link feature to intercept SMS-based one-time passwords (OTPs) and other sensitive data from…
7 articles · Updated May 5, 2026 -
Russian APT Campaign Targets Ukraine with BadPaw and MeowMeow Malware
A Russian cyber campaign has been identified targeting Ukrainian organizations using new malware families, BadPaw and MeowMeow, delivered via phishing emails. The operation begins with emails containing links to ZIP…
4 articles · Updated March 5, 2026 -
Revival of Finger Command in ClickFix Malware Attacks
Threat actors are exploiting the decades-old 'finger' command in new ClickFix malware attacks to execute remote commands on Windows devices. The command, which was historically used to retrieve user information on Unix…
4 articles · Updated November 17, 2025 -
Revival of 'Finger' Command in ClickFix Malware Attacks
Threat actors have reintroduced the decades-old 'finger' command in new ClickFix malware attacks to facilitate remote command execution on Windows devices. The command, originally used for user information retrieval on…
2 articles · Updated November 17, 2025
Recent Intelligence Reports
- New Infostealer Dubbed ‘Pheno’ Hijacks Windows’ Phone Link App to Steal MFA OTPs — Thecyberexpress · May 5, 2026
- CloudZ RAT potentially steals OTP messages using Pheno plugin — Blog.Talosintelligence · May 5, 2026
- Multi-Stage "BadPaw" Malware Campaign Targets Ukraine — Infosecurity-Magazine · March 4, 2026
- New ClickFix attacks reuse ancient 'finger' command — Scworld · November 17, 2025
- Decades-old ‘Finger’ protocol abused in ClickFix malware attacks — Bleepingcomputer · November 15, 2025