By: Max Gannon, Cofense Intelligence
Cofense Intelligence is observing a clear change in phishing operations. Threat actors are moving beyond broad, one-size-fits-all delivery and adopting platform-aware workflows that adapt to the victim’s device, browser, and environment. What began primarily as Windows-focused malware distribution has evolved into campaigns that can selectively deliver credential phishing, remote-access tools, or malware across Windows, macOS, and Android.
This change is designed to improve compromise rates, expand target coverage, and increase the attacker’s return on the same lure and infrastructure.
Traditional Phishing Campaigns
Traditional campaigns often used simple emails, inconsistent narratives, and basic infection chains. Attached archives containing malicious scripts were a common way to bypass secure email gateways (SEGs). These operations were uncomplicated, but they remained effective.
As perimeter controls improve, threat actors are adjusting their delivery models. Obvious malicious attachments are appearing less often in many inboxes, while adaptive, multi-stage campaigns use trusted brands, embedded links, device fingerprinting, and legitimate remote-access tools to create different outcomes for different victims. This is not simply better evasion at the message level; it is campaign infrastructure designed to mutate.
Figure 1: An email from a traditional phishing campaign with an attached archive containing a script that runs malware. This corresponds to Active Threat Report (ATR) 389255.

Figure 2: A very simplistic infection chain leading to the execution of Ave_Maria Stealer.
Cofense Active Threat Reports (ATRs) document these campaigns from the original email and subject-line themes through file hashes, network indicators of compromise (IOCs), payloads, and related infrastructure. That campaign context becomes increasingly important as delivery paths diverge by platform.
Modern Phishing Campaigns
Modern campaigns use narratives tailored to the recipient and provide plausible reasons to click an embedded link. The link can begin a multi-stage chain that fingerprints the victim before selecting the next action.
Figure 3: An email from a modern phishing campaign targeting a victim belonging to a veterinarian company that contains an embedded URL leading to a phishing site that detects the operating system of the victim. This corresponds to ATR 411478.

Figure 4: A more complex infection chain staring with the email in Figure 3 involving two steps of fingerprinting that leads to either credential phishing or Ninite Loader. Ninite Loader then delivers ConnectWise RAT depending on the local environment.
Multi-Platform Delivery
Threat actors use browser and operating-system information to tailor the content presented after a victim clicks. The browser “User-Agent” is a common source of device and software details, and some campaigns also embed the victim’s email address or other identifiers in the URL. The resulting page may display a credential form, deliver malware, or redirect the visitor based on the environment.
Attackers use several methods to fingerprint and uniquely identify victim systems. In some campaigns, that information only controls the delivered content; in others, services such as Telegram are used to store or exfiltrate the collected information.
Platform Determination Methods
Threat actors can use Cloudflare capabilities, open-source fingerprinting projects, or scripts embedded directly in a phishing kit. Although the implementations vary, the most common collected attributes include:
- Browser type
- Operating system or device type
- Language
- Local time and time zone
- Screen and browser-window dimensions
- Geolocation
Some of the basic information collected is shown in Figure 5.

Figure 5: Basic information collected by one of the many open-source multi-platform kits, excessive documentation ensures even minimally skilled threat actors can take advantage of these tools.
Cloudflare User-Agent rules are also appearing more often. These rules can redirect traffic based on the perceived operating system before the visitor reaches the malicious page, allowing an attacker to tailor delivery without maintaining a separate custom detection script.
Malware Delivery Kits
Multi-platform kits can deliver malware and credential phishing from the same workflow. The most frequently impersonated brands in the analyzed campaigns included Google, DocuSign, Microsoft Teams, Adobe, and Zoom.
- DocuSign
- Microsoft Teams
- Adobe
- Zoom
Figure 7: The landing page seen in ATR 41211 which delivers Itarian RAT to Windows based browsers and is designed to deliver relevant payloads for other operating systems. Itarian RAT then further fingerprints the victim’s machine and potentially delivers ConnectWise RAT.
Many of the delivered tools are technically legitimate remote-access applications repurposed as remote-access trojans. Because the same products may be used by internal IT teams, automated defenses can struggle to distinguish authorized administration from malicious use without the surrounding email and campaign context.
Credential Phishing Kits
The credential-phishing pages used in multi-platform campaigns are often simpler than the malware-delivery pages. Many request any email address and password rather than reproducing one specific service. Different logos may be applied to the same underlying form so the attacker can monetize visitors who are not suitable for the malware path.
Figure 8: The landing page for ATR 413611 which delivered ConnectWise RAT for Windows based operating systems and the shown credential phishing page for MacOS or Android.
Figure 9: The landing page for ATR 411787 which delivered Itarian RAT for Windows based operating systems and the shown credential phishing page for MacOS or Android.
Motivation of Multi-Platform Targeting
The motivation is economic. By detecting the victim’s device and delivering the most useful payload for that environment, attackers avoid losing a click simply because the target is using macOS, Android, or another unsupported platform. The same lure and infrastructure can generate stolen credentials, remote access, or host intelligence across a broader population.
Threat Actor Economics: Maximizing ROI
A single lure, landing page, and delivery process can support several operating systems, reducing infrastructure costs and minimizing wasted traffic. Successful access can later be monetized through initial-access broker activity: attackers establish persistence, conduct reconnaissance, and sell access to another criminal group. That downstream access is one path by which phishing can contribute to ransomware incidents.
Implications of Multi-Platform Targeting
The shift has strategic and operational consequences. Strategically, organizations can no longer assume that a specific operating system or device type is inherently safer. Operationally, security architectures built around platform silos are poorly suited to recognize one phishing operation that produces different outcomes across Windows, macOS, and mobile devices.
The attack surface is expanding while defenders’ ability to correlate activity across it is often shrinking.
The End of Platform Safety Assumptions
Statements such as “we do not use Windows” or “mobile users are lower risk” are no longer meaningful defenses when each device can be fingerprinted and monetized differently. Devices outside standard enterprise controls can be especially attractive because visibility and policy enforcement are less consistent.
Why Platform-Centric Security Is Failing
Most tools monitor a platform, endpoint, or network segment—not the campaign moving across them. A Windows endpoint product may identify a RAT while the macOS credential page goes unlogged and a mobile compromise occurs outside company infrastructure. The attacker is running one operation, but the organization sees several small and apparently unrelated incidents.
Independent baselines and thresholds can also understate the campaign’s scope. Activity spread across Windows, macOS, and mobile may remain below the threshold on each individual platform even when the combined impact is significant. Without shared identity and session context, attribution becomes harder and response remains fragmented.
From Platform-Aware Delivery to Campaign-Aware Defense
Device-aware campaigns expose a limitation of single-message detection: the same operation can produce a Windows malware path, a macOS credential page, and an Android-specific experience while sharing the same underlying structure and intent. Exact IOC matching may identify one branch and miss the others.
Cofense Vision 3.2 shifts response from individual emails to campaign-level action. Vision AI uses clustering and pattern matching to connect related messages that vary in sender, subject, URL, content, or delivered payload but share structural relationships. When one threat is confirmed, quarantine can cascade across the related cluster through analyst-controlled workflows. New intelligence can also be applied retroactively, removing older campaign variants that were already delivered.
Summary
Threat actors once sent the same email to a large audience and relied on a small percentage of recipients to click. Increasingly, they identify the device first and deliver an outcome tailored to that environment—all from the same email and campaign infrastructure. A Windows user may receive a remote-access tool, while a colleague on a Mac or phone sees a convincing credential page. The attacker can profit either way.
Modern phishing is platform-aware. Defense must be campaign-aware. Organizations need post-perimeter visibility that combines real-world phishing intelligence, AI-driven correlation, and expert validation so their teams can understand the full operation—not just the one variant that was reported.
Cofense delivers phishing-specific AI trained on expert-validated, real-world phishing intelligence, with explainable decisions, analyst control, and a full audit trail. See how Vision helps security teams identify polymorphic campaigns and respond across the email environment.