Back Darkreading Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability.
Threat actors are moving away from spray-n-pray phishing attacks in favor of campaigns that can automatically adapt to a target's device and operating system.
Today, anti-phishing security vendor Cofense published research covering the cutting-edge ways threat actors are upping their phishing game. As research post author Max Gannon of Cofense Intelligence explained, classic phishing attacks often have clumsy, simple emails and an attachment with a simple infection chain that could bypass secure email gateways. Many modern campaigns now use emails targeted and tailored to the victim, with complex narratives relevant to the target (such as delivering an invoice for a business manager) and more complex infection chains.
More recently, Cofense has seen examples of phishing campaigns that are even more targeted once the victim clicks a link or an attachment. It is at that stage that the attachment or landing page collects information for the user-agent provided by the browser; user-agent data is a string of text data that Web browsers and applications send when a Web page is loaded. Through this data, the attacker can fingerprint and collect data including victim email addresses, browser information, device information, language, victim local time, screen and window size, and geolocation.
"One method of detection that is appearing more often is the use of Cloudflare user-agent blocking, which redirects traffic based on the perceived operating system of the browser before the victim even visits the malicious page," the research read. "This enables threat actors to deliver customized payloads without having to add their own detection scripts."
This data is often used to deliver the right malware to the right user; one example Cofense cited was a phishing landing page that delivered FleetDeck for macOS or Tiflux RAT for Windows, depending on what attackers detected during fingerprinting. Much of the malware Cofense has observed in multiplatform campaigns has been "technically legitimate remote access tools (RATs) that have been repurposed to act as remote access trojans (Also RATs)," as they're much harder for automated defenses to detect.
Moreover, "threat actors are progressively using tools like Telegram to exfiltrate and save the information more often," Gannon wrote.
Multiple campaigns have been observed using platform-aware tactics, and similar tactics are used for the deception component as well. Phishing landing pages will make decisions to mimic Google, Docusign, Microsoft Teams, Adobe, and Zoom download screens based on telemetry picked up from the victim's browser.
It is no surprise that phishing actors have stepped up their game up in recent years. Large language models (LLMs) have made it so attackers around the world can generate phishing emails in perfect English in no time at all; phishing kits have offered low-level attackers the ability to conduct sophisticated attacks they couldn't pull off otherwise; and social engineering attacks continue to get trickier, thanks to emerging tactics like ClickFix .
As for these new platform-aware techniques, the reason behind them is simple: better economics for the attacker.
"By building campaigns that can identify a victim's device and deliver the most effective payload for that environment, threat actors can reach more targets, increase the likelihood of compromise, and extract more useful information from each interaction," Gannon wrote. "Instead of losing traffic when a victim is on macOS, Android, or another unsupported platform, threat actors can still monetize the click-through credential theft or customized remote access tools. In practice, this means greater profit, broader target coverage, and higher return on investment from the same lure, infrastructure, and campaign effort."
The campaigns Cofense describes are standard phishing campaigns with some trickier moves once an email recipient clicks a malicious link.
Like so many other phishing campaigns, best practices work well here. Phishing-resistant authentication methods like FIDO2 keys are generally sound considerations, as is employee training on the modern ways threat actors conduct phishing and social engineering campaigns. There are also a wide range of security products that aim to prevent such attacks from ever reaching employee inboxes.
Gannon tells Dark Reading that the core message for security leaders is that the most important thing to do is close the cross-platform visibility gap by unifying monitoring across Windows, Mac, and mobile, so activity is appropriately viewed as a single campaign.
He also recommends building visibility "into what happens after the click, meaning the redirect chains and device-specific delivery logic, rather than relying solely on blocking the first email." Moreover, one of the most valuable resources for stopping phishing are one's own employees.
"Organizations," he says, "should also treat their people as a primary sensor rather than a last line of defense, since threat actors increasingly repurpose trusted remote access tools like ConnectWise RAT that signature-based defenses will rarely flag, and it is usually a trained employee, not an automated scanner, who recognizes that an unexpected tool is out of place."
Senior News Writer, Dark Reading
Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Security, Nintendo World Report, and elsewhere.
At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.
He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.
The State of Cloud Security: The Latest Challenges
The total economic impact™ of Snyk
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything
Practical Zero Trust Implementation on a Budget in the Age of Mythos
Building a Risk Based Vulnerability Management Program
Threat Hunting That Gets Big Results Despite Small Budgets
Say Yes to AI: Securing Innovation Without Compromise
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
