CloudZ RAT and Undocumented Pheno Plugin Used in Credential Theft Intrusion
Patch or remove the Pheno plugin immediately and monitor for CloudZ RAT activity.
Patch or remove the Pheno plugin immediately and monitor for CloudZ RAT activity.
Summary
Cybersecurity researchers have exposed a recent intrusion that leveraged the CloudZ remote access tool (RAT) in conjunction with an undocumented WordPress plugin called Pheno. The attackers used CloudZ to remotely control infected systems and exfiltrate user credentials, including one‑time passwords (OTPs). Pheno, which had never been publicly documented, was exploited to facilitate the credential theft by providing a foothold for the RAT. The intrusion was discovered through forensic analysis of compromised sites and detailed in a research report released on 5 May 2026.
The report highlights that the attackers targeted sites with the Pheno plugin installed, using it to bypass authentication mechanisms and inject the CloudZ RAT payload. No public patch or update for Pheno has been issued, and the CloudZ RAT remains an active threat vector. WordPress site owners are urged to audit their plugins for the presence of Pheno and to monitor for suspicious remote access activity. The incident underscores the importance of maintaining an up‑to‑date plugin inventory and employing security monitoring tools.
This breach demonstrates how an undocumented plugin can become a critical vulnerability when combined with a powerful RAT. The researchers recommend immediate action to remove or replace Pheno and to implement stricter access controls. The findings also serve as a warning that even seemingly innocuous plugins can be leveraged for large‑scale credential theft.
Key changes
- CloudZ RAT was used to remotely control infected WordPress sites
- Pheno plugin, previously undocumented, was exploited to facilitate credential theft
- Attackers targeted one‑time passwords (OTPs) as well as standard credentials
- Researchers disclosed intrusion details on 5 May 2026
- No public patch for Pheno has been released yet
- CloudZ RAT remains an active threat vector
- WordPress sites with Pheno installed are at highest risk
- The incident highlights the need for plugin inventory audits