Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting — Threadlinqs Intelligence
As of 2026-07-05, Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1126 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Cofense Intelligence, reported by Dark Reading on 2026-07-01, documents a shift in phishing tradecraft: landing pages fingerprint victims via User-Agent and browser telemetry (device info, language,
Cofense Intelligence describes a clear evolution in phishing operations: campaigns that were once simple, Windows-only malware droppers now perform User-Agent/browser fingerprinting on a single landing page and branch the attack chain according to the victim's detected operating system. The fingerprinting script harvests the victim's email address (often pre-filled from the phishing link), browser/device information, language, local time, screen and window size, and geolocation, then uses that data — and in some observed cases Cloudflare User-Agent-based edge redirects that route traffic by perceived OS before the victim ever reaches the malicious page — to decide which lure and payload to serve.
On Windows, victims are served either a Tiflux RAT installer or, in a related fingerprinting chain also documented by Cofense, an Itarian RAT payload that further fingerprints the host and hands off to a Ninite Loader which in turn deploys a ConnectWise (ScreenConnect) remote-access payload. On macOS, the same landing page instead serves FleetDeck, a boutique legitimate remote-monitoring-and-management (RMM) agent that is repurposed as unauthorized remote access, or redirects the victim to a credential-phishing page mimicking a trusted brand. Android visitors are likewise redirected to credential-harvesting pages rather than served an executable payload. Across variants, the decoy landing pages are dynamically dressed to resemble Google, Docusign, Microsoft Teams, Adobe, or Zoom download or sign-in screens depending on the fingerprint collected, maximizing the credibility of the lure for the victim's actual software environment.
The Windows RAT-delivery vector cited in the Cofense/Dark Reading reporting overlaps technically with a Tiflux RMM malspam cluster analyzed in depth by Huntress beginning around 2026-02-27: phishing emails impersonating a 'Network Solutions Service Agreement' route victims through a Cloudflare CAPTCHA-gated landing page (lenwillfilenetwork.com) that displays a spoofed macOS-style CAPTCHA popup even to Windows browsers, then serves an MSI installer (Network Solutions Agreement.msi / Adobeclient-33.2.msi) signed by 'Tiflux Sistema de Gestão LTDA.' The resulting Tiflux agent establishes a TiPeerToPeer UDP backchannel, profiles the host via osqueryl.exe, captures and transmits screenshots, and daisy-chains additional remote-access tools (UltraVNC 1.2.0.1 with an expired 2014 certificate, Splashtop, and ScreenConnect) for redundant access. A known-vulnerable, long-expired-certificate driver (HwRwDrv.sys) capable of privilege escalation is also dropped without clear operational justification, and the malware installs SSH host keys for passwordless PuTTY access and disables Windows Secure Attention Sequence notifications. Build-path metadata ties the toolkit to a 'PeopleOne' developer identity, and its SSH C2 endpoint (remote1a.peopleone.com.br) went offline around 2026-05-07.
A second, closely related cluster documented by Microsoft (2026-03-03) shows the same brand-impersonation lure set — fake meeting invitations and document notifications spoofing Microsoft Teams, Zoom, Adobe Reader, Google Meet, and DocSign — delivering executables signed with an abused Extended Validation certificate issued to 'TrustConnect Software PTY LTD.' These droppers (Microsoft Defender family names Kepavll/Screwon) install ScreenConnect, Tactical RMM, and MeshAgent as backdoors, registering a Windows service and a Run-key persistence entry, and reach out to a dedicated C2 domain set (trustconnectsoftware.com, turn.zoomworkforce.us, rightrecoveryscreen.top, smallmartdirect.com) and IP infrastructure. This TrustConnect cluster is not confirmed by Cofense to be the identical operation described in the fingerprinting report, but it demonstrates the same brand-impersonation-plus-RMM-backdoor tradecraft that the fingerprinting campaign's Windows/macOS lures rely on, and is documented here as directly relevant supporting evidence for the lu
Weaknesses (CWE)
CWE-451, CWE-494, CWE-829
Target sectors: finance, health, government administration, professionalservices, manufacturing, technology, retail, legal
Target regions: Global, North America, Europe, 005 - South America
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1566.001, T1566.002, T1189, T1204.001, T1204.002, T1059.001, T1218.007, T1547.001, T1543.003, T1547.014