Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands.
CloudZ RAT exploits Phone Link since Jan 2026, stealing credentials and OTPs via Pheno plugin, bypassing 2FA protections.