Phishing Emails Now Study Your Phone Before They Attack You
A new wave of scam emails quietly profiles your device, your operating system and your screen size, then delivers malware tailored specifically to your setup.

Key points
- Cofense, an anti-phishing security company, published research in 2025 showing that phishing campaigns now fingerprint victims' devices before delivering malicious software.
- Criminals use freely available browser data, called a "user-agent string," to detect whether a target runs Windows, macOS, Android, or another operating system.
- One documented campaign delivered FleetDeck malware to macOS users and Tiflux RAT, remote access software repurposed by criminals to spy on victims, to Windows users, automatically.
- Criminals are increasingly routing stolen data through Telegram, the messaging app, to receive harvested passwords and device information in real time.
- Max Gannon of Cofense told Dark Reading that a trained employee who notices something unexpected will often catch what automated scanners miss.
A phishing email, a fake message designed to trick you into clicking a harmful link, used to be a clumsy, scattershot thing. Bad spelling, generic subject lines, one malicious attachment sent to a million people. That era's ending.
Research published this week by Cofense describes something more surgical. Click a link in one of these newer scam emails and the landing page quietly reads data your browser sends automatically. Every browser announces itself to every website it visits. That announcement, called a user-agent string, reveals your operating system, browser type, device, language, local time, screen size, and geolocation. You can't turn it off.
Criminals are now using that data as a targeting system.
How do criminals use your browser's data against you?
They use it to decide which malicious software to send you. Your browser signals Mac: you get one payload. It signals Windows: you get another. Cofense documented exactly this split, a single phishing page delivering FleetDeck to macOS users and Tiflux RAT, a remote-access tool hijacked to take control of a victim's computer, to Windows users, with no human decision required.
This closes a gap attackers used to lose money on. A Windows-only attack wasted every Mac click. Now it doesn't.
One technique Cofense flagged: some campaigns use Cloudflare's traffic-routing tools to redirect victims based on their detected operating system before they even reach the malicious page, so the attacker doesn't need custom detection scripts at all. The deception layer follows the same logic. Landing pages will mimic Google, DocuSign, Microsoft Teams, Adobe, or Zoom depending on what the browser fingerprint suggests will look most convincing. Stolen data then travels out through Telegram rather than traditional servers, making the trail harder to follow.
The economics are straightforward. One campaign, one piece of infrastructure, every platform covered, higher return per click.
Should you worry?
The short answer is yes, though the response isn't complicated. Gannon's advice to Dark Reading was to unify monitoring across Windows, Mac, and mobile so that unusual activity across devices registers as one connected campaign rather than isolated noise. He also recommended building visibility into what happens after a user clicks, meaning the redirect path and device-specific delivery logic, rather than focusing only on blocking the first email.
For individuals, suspicion toward any unexpected download prompt or login page remains the right instinct, even when the page looks exactly like Google or Adobe. Gannon's core point, reported by Dark Reading, is that a trained employee recognising an unexpected tool on their computer will catch what signature-based defences routinely miss. Our 3 July report on TA558 made a similar observation: compressed-file tricks succeed precisely because automated filters don't flag what looks legitimate.



