Security researchers have flagged a new risk to users of Microsoft's Phone Link application. An unidentified threat actor is using the tool to steal SMS messages and one-time passwords.
The attack leverages a known remote access trojan that has been updated with fresh capabilities. These changes allow the malware to target data synced between Android phones and Windows computers through the Phone Link service.