Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.”
First seen on blog.talosintelligence.com
Jump to article: blog.talosintelligence.com/cloudz-pheno-infostealer/
![]()

