- What: Phishing campaigns adapt to victim's device and OS
- Impact: Users may be targeted with tailored phishing attacks
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Application Security Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS by Alexander Culafi Jul 1, 2026 4 Min Read Cyber Risk Fake Bug Report Hijacks AI Coding Agents at Scale Fake Bug Report Hijacks AI Coding Agents at Scale by Jai Vijayan Jun 30, 2026 4 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Application Security Data Privacy Cyberattacks & Data Breaches Identity & Access Management Security News Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability. Alexander Culafi , Senior News Writer , Dark Reading July 1, 2026 4 Min Read Source: imagebroker/markus gann via Getty Images Threat actors are moving away from spray-n-pray phishing attacks in favor of campaigns that can automatically adapt to a target's device and operating system. Today, anti-phishing security vendor Cofense published research covering the cutting-edge ways threat actors are upping their phishing game. As research post author Max Gannon of Cofense Intelligence explained, classic phishing attacks often have clumsy, simple emails and an attachment with a simple infection chain that could bypass secure email gateways. Many modern campaigns now use emails targeted and tailored to the victim, with complex narratives relevant to the target (such as delivering an invoice for a business manager) and more complex infection chains. More recently, Cofense has seen examples of phishing campaigns that are even more targeted once the victim clicks a link or an attachment. It is at that stage that the attachment or landing page collects information for the user-agent provided by the browser; user-agent data is a string of text data that Web browsers and applications send when a Web page is loaded. Through this data, the attacker can fingerprint and collect data including victim email addresses, browser information, device information, language, victim local time, screen and window size, and geolocation. Related: New Initiative Tackles Security for End-of-Life Open Source Software "One method of detection that is appearing more often is the use of Cloudflare user-agent blocking, which redirects traffic based on the perceived operating system of the browser before the victim even visits the malicious page," the research read. "This enables threat actors to deliver customized payloads without having to add their own detection scripts." The Right Phishing Payload for the Right Victim This data is often used to deliver the right malware to the right user; one example Cofense cited was a phishing landing page that delivered FleetDeck for macOS or Tiflux RAT for Windows, depending on what attackers detected during fingerprinting. Much of the malware Cofense has observed in multiplatform campaigns has been "technically legitimate remote access tools (RATs) that have been repurposed to act as remote access trojans (Also RATs)," as they're much harder for automated defenses to detect. Moreover, "threat actors are progressively using tools like Telegram to exfiltrate and save the information more often," Gannon wrote. Multiple campaigns have been observed using platform-aware tactics, and similar tactics are used for the deception component as well. Phishing landing pages will make decisions to mimic Google, Docusign, Microsoft Teams, Adobe, and Zoom download screens based on telemetry picked up from the victim's browser. Related: Robinhood Cuts Access Approval Time to Support High-Velocity Development It is no surprise that phishing actors have stepped up their game up in recent years. Large language models (LLMs) have made it so attackers around the world can generate phishing emails in perfect English in no time at all; phishing kits have offered low-level attackers the ability to conduct sophisticated attacks they couldn't pull off otherwise; and social engineering attacks continue to get trickier, thanks to emerging tactics like ClickFix . As for these new platform-aware techniques, the reason behind them is simple: better economics for the attacker. "By building campaigns that can identify a victim's device and deliver the most effective payload for that environment, threat actors can reach more targets, increase the likelihood of compromise, and extract more useful information from each interaction," Gannon wrote. "Instead of losing traffic when a victim is on macOS, Android, or another unsupported platform, threat actors can still monetize the click-through credential theft or customized remote access tools. In practice, this means greater profit, broader target coverage, and higher return on investment from the same lure, infrastructure, and campaign effort." Related: Apple's MacOS Gap Lets Users Disable Security Tools Just Another Phishing Campaign The campaigns Cofense describes are standard phishing campaigns with some trickier moves once an email recipient clicks a malicious link. Like so many other phishing campaigns, best practices work well here. Phishing-resistant authentication methods like FIDO2 keys are generally sound considerations, as is employee training on the modern ways threat actors conduct phishing and social engineering campaigns. There are also a wide range of security products that aim to prevent such attacks from ever reaching employee inboxes. Gannon tells Dark Reading that the core message for security leaders is that the most important thing to do is close the cross-platform visibility gap by unifying monitoring across Windows, Mac, and mobile, so activity is appropriately viewed as a single campaign. He also recommends building visibility "into what happens after the click, meaning the redirect chains and device-specific delivery logic, rather than relying solely on blocking the first email." Moreover, one of the most valuable resources for stopping phishing are one's own employees. "Organizations," he says, "should also treat their people as a primary sensor rather than a last line of defense, since threat actors increasingly repurpose trusted remote access tools like ConnectWise RAT that signature-based defenses will rarely flag, and it is usually a trained employee, not an automated scanner, who recognizes that an unexpected tool is out of place." About the Author Alexander Culafi Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. See more from Alexander Culafi Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impactâ„¢ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets Say Yes to AI: Securing Innovation Without Compromise Zero Trust Identity: Beyond Traditional Authentication More Webinars Editor's Choice Cybersecurity Operations Do CISOs Need a Code of Ethics? Do CISOs Need a Code of Ethics? by Dark Reading Editorial Team Jun 24, 2026 Cybersecurity Operations 2026 FIFA World Cup Faces Surge in Cyber Threats 2026 FIFA World Cup Faces Surge in Cyber Threats by Alexander Culafi Jun 24, 2026 3 Min Read Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. Subscribe Aug 1-6 | Mandalay Bay, Las Vegas Use code: DARKREADING & save $200 on a Briefings pass or $100 on a Business pass The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us Newsletter Sign-Up Follow Us Copy