Mobile cloaking explained: one URL, two realities
Open a suspected phishing link on your office laptop and you might see a harmless blog about garden furniture. Open the exact same link on a phone, on a mobile network, in the country being targeted, and you get a login screen demanding your password. Same URL, two completely different pages. This is cloaking, and it is the single most effective trick keeping phishing pages alive today.
Understanding it matters because almost every automated defence can be fooled by it — and almost every manual takedown stalls because of it. Here is how cloaking works, why it is so effective, and how dual-profile crawling defeats it.
One URL, two realities
A cloaked phishing page is not one page. It is a decision engine sitting in front of two pages. When a request arrives, the engine inspects the visitor and decides which reality to serve:
- The decoy — a clean, innocuous page shown to anyone who looks like a search crawler, a security scanner, a researcher, or simply the wrong kind of visitor.
- The trap — a convincing clone of a real login page, shown only to the visitors the attacker actually wants: real phones, on mobile networks, in the targeted region.
your-brand-login.help/secureYour session has expired
Re-enter your details to restore access.
EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COMThe same link: a clean article to a crawler (left), a credential trap to a real mobile visitor (right).
How the page decides who you are
Modern phishing kits fingerprint every visitor in milliseconds before choosing which page to render. The signals they lean on include:
- User-agent string — is this Googlebot, a headless browser, or a real mobile Safari or Chrome?
- IP address and ASN — does the address belong to a hosting provider or a cloud scanner, or to a residential mobile carrier in the target country?
- Geolocation — visitors outside the targeted region are almost always served the decoy.
- Headers and language — accept-language, referer and header order all hint at whether a human on a phone is really behind the request.
- JavaScript and touch checks — some kits run a quick script to confirm a touchscreen and real screen dimensions before revealing the trap.
If any signal looks like a bot or a researcher, the kit quietly serves the clean page. The attacker would rather miss a few real victims than expose the trap to the people who could report it.
The practical result: the automated scanner that is supposed to catch the page sees the decoy and marks it safe. The page stays live, and your customers — on their phones — keep hitting the trap.
Why cloaking beats ordinary defences
Most brand-protection and safe-browsing systems crawl from data-center IP ranges with bot-like user agents. That is exactly the profile a cloaking kit is built to recognise and deflect. So three things happen at once:
- Automated classifiers see a clean page and never flag it.
- When a human finally reports it, the abuse desk also loads the clean page — and dismisses the report as a false positive.
- The attacker buys days of uptime, which is all a phishing campaign needs to harvest credentials and move on.
In other words, cloaking does not just hide the crime from scanners. It actively discredits the people trying to report it.
Defeating the cloak: crawl as both
The only reliable way to beat cloaking is to refuse to be fingerprinted as a single kind of visitor. That means crawling each suspect URL at least twice, from deliberately different profiles:
- A search-crawler profile — the view the attacker wants the world to see.
- A real in-country mobile profile — a genuine mobile user-agent, from a residential or mobile IP in the targeted region, with the headers and behaviour of an actual phone.
Then you diff the two responses. If the mobile profile receives a login trap while the crawler profile receives a clean page, the cloak is proven. The difference itself is the evidence.
This is exactly how Phish Plug works. Every suspect URL is fetched as a crawler and as a real in-country phone through an in-country proxy pool, and the two responses are diffed automatically to expose and document the hidden redirect.
Turning the cloak into evidence
Once you can see both realities, the cloak stops being the attacker's shield and becomes their liability. A strong case captures:
- Screenshots from both profiles, side by side.
- The raw HTTP response headers for each, so the difference is verifiable rather than visual.
- The resolved redirect chain that leads a mobile visitor to the trap.
- A timestamp for each capture, establishing a clean chain of custody.
Presented with that, an abuse desk no longer sees a dubious screenshot. It sees proof that one URL is lying to crawlers — which is precisely the behaviour that justifies removal. This is why evidence-backed, cloak-proving reports are accepted on first submission far more often than a lone screenshot ever is.
The takeaway
Cloaking is not an exotic edge case; it is the default behaviour of modern phishing. If your brand protection only crawls like a bot, you are seeing the page the attacker wants you to see. Seeing the other reality — the one your customers actually get — is the whole game. Crawl as both, diff the results, and the trick that kept the clone alive becomes the evidence that takes it down.
Keep reading
Related articles
Typosquatting vs. homoglyph attacks, explained
Two ways attackers fake your domain — one exploits typing mistakes, the other uses look-alike characters. How each works and how to catch both early.
Read article Takedowns · 8 minThe phishing takedown process: abuse channels, step by step
Registrars, hosts, CDNs and safe-browsing desks — where to file, what evidence each one wants, and why routing beats blasting.
Read article Threats · 8 minWhat is credential harvesting? How phishing steals logins
Credential harvesting is the engine behind most phishing. How fake login pages capture passwords, where the data goes, and how to shut the pipeline down.
Read articleSee cloaking resolved on your own domain
Run a free clone check — Phish Plug crawls as a bot and a real phone, then shows you the diff.