Cloaking hides the crime
Automated scanners see the clean page, so the trap passes checks and stays online for days.
Phish Plug hunts phishing clones of your brand, cracks the mobile cloaking they hide behind, captures the evidence, and files the takedowns — all from one panel.
The cloaking trick
The same phishing link shows a search crawler a clean page and real in-country mobile visitors a credential trap. Phish Plug sees both.
aurora-bonus.net/loginRe-enter your details to restore access.
EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COMWorldwide reach
Phishing infrastructure sprawls across registrars, hosts and CDNs in dozens of countries. Phish Plug resolves the cloak, captures court-ready evidence, and files the takedown to the right desk — wherever the clone lives.
The problem
Manual takedowns lose to automation. By the time a clone is spotted, reported by hand and finally removed, it has already harvested credentials — and the next one is live.
Automated scanners see the clean page, so the trap passes checks and stays online for days.
Finding the right abuse desk and writing each report by hand costs hours the attacker uses to cash out.
A screenshot alone is easy to dismiss. Desks need the cloaking diff and raw headers to act quickly.
How it works
Continuous monitoring watches new domain registrations, lookalike patterns, backlinks and search results for anything impersonating your brand.
Phish Plug crawls each suspect as a search bot and as a real in-country phone, then diffs the responses to expose the hidden redirect.
Screenshots from both profiles, raw headers and the cloaking diff are bundled into a court-ready case the moment impersonation is confirmed.
With one human approval, the right report is routed to the registrar, host, CDN or safe-browsing desk — and the clone is tracked to removal.
The platform
24/7 watch for cloned login pages and lookalike domains across registrars, hosts and search.
Dual-profile crawling with an in-country proxy pool to resolve and prove mobile cloaking.
Screenshots, raw headers and diffs stored per case — exportable and built to be accepted.
Nothing is sent without a click. Route to six abuse channels across 24+ desks worldwide.
A clear live timeline for every threat, from first sighting to confirmed removal.
Pull cases, diffs and status into your own stack; sign in with SSO and keep an audit log.
Why Phish Plug
| Capability | Manual takedowns | Generic domain monitoring | Phish Plug |
|---|---|---|---|
| Finds lookalike clones | |||
| Defeats mobile cloaking | |||
| Court-ready evidence bundle | Partial | ||
| Routes to the right abuse desk | Partial | ||
| Median time to filing | Hours–days | Alert only | 37 minutes |
| Human approval before sending | N/A |
FAQ
Phish Plug is an automated brand-protection platform. It continuously watches for phishing clones and lookalike domains impersonating your brand, cracks the mobile cloaking they hide behind, captures court-ready evidence, and files takedown requests to the right registrars, hosts and safe-browsing desks — all from a single panel.
Cloaking is when one URL serves two different pages: a clean, harmless page to search crawlers and a credential-stealing trap to real in-country mobile visitors. It lets phishing pages pass automated checks and stay online longer. Phish Plug crawls as both a bot and a real phone, diffs the two responses, and proves the redirect so takedown desks act fast.
Median time from detection to a filed, evidence-backed takedown is 37 minutes. Every clone is verified before anything is sent, and nothing leaves the panel without a human approval, so real sites are never touched.
No. Detection is always followed by verification. A clone is only actioned once the cloaking diff and evidence confirm impersonation, and sending is gated behind a one-click human approval. Accuracy — not volume — is the point.
Registrars, hosting providers, CDNs and safe-browsing desks — six abuse channels in total, across more than 24 takedown desks worldwide. The right report is routed to the right desk automatically, wherever the clone is hosted.
Yes. Every case ships with screenshots from both crawler profiles, raw response headers, the cloaking diff and a full Detected → Removed timeline. It is designed to be accepted by abuse desks on the first submission — our evidence-accepted rate is 99%.
Run a free clone check on one domain — cloaking diff and an evidence sample included.