6 min read

The New Arms Race in Cybercrime: Who Looks Like a Real Victim?

Facebook logo
Facebook logo
X (formerly Twitter) logo
X (formerly Twitter) logo
LinkedIn logo
LinkedIn logo
Reddit logo
Reddit logo


Detecting phishing sites has never been easy. For years, defenders have raced attackers to identify malicious infrastructure before it could harm victims.  

But recently, an additional challenge has emerged: increasingly sophisticated filtering systems that determine who gets to see an attack in the first place. 

Finding a suspicious URL is often only the first step. Security teams must also overcome layers of cloaking, fingerprinting, and visitor validation before they can observe the attack victims actually encounter. 

Security teams investigating suspicious URLs increasingly encounter a frustrating scenario: A customer reports a phishing page, analysts visit the URL, but nothing is there. Maybe they get redirected to a legitimate website or see a blank page, or a generic error.  

Meanwhile, victims are still seeing the page just fine, and they’ve already lost their money or login credentials. 

That disconnect highlights one of the biggest shifts happening in cybercrime right now: Attackers have become remarkably good at deciding who gets to see their phishing infrastructure and who doesn't. 

And in response, defenders have found themselves in an unexpected competition. 

Attackers are building increasingly sophisticated ways to identify real victims, while defenders are working to experience attacks the same way those victims do. 

Attackers aren't hiding websites anymore — they're filtering visitors

Terms like “cloaking” or “geofencing” typically conjure images of attackers hiding infrastructure behind technical tricks. 

Modern phishing operations still rely on technical tricks such as cloaking and geofencing, but many now resemble fraud-prevention systems. Before serving content, they evaluate a wide range of signals about a visitor and determine whether that visitor appears to be a genuine target, a security researcher, or an automated scanner. 

“Phishing sites have become way more focused on validating their users,” Charlie Hothersall-Thomas, Netcraft’s director of engineering, said. “Nowadays, it's not just geofencing, it’s all the way down the stack. It’s all about consistency. For example, well... you say you’re in this location, but what’s the time on your device’s clock? What sort of device do you have? What’s your screen resolution? Are you moving your cursor? Any extensions installed? How did you get here? Have you visited any of my sites before?” 

Some phishing campaigns only appear when visitors arrive through a specific SMS campaign or advertisement. Others inspect browser settings, device characteristics, extensions, rendering capabilities, or signs that the visitor might be an automated scanner. 

One layer might not stop a security team, but five or six could. 

"It's additive, right? The more of this stuff that we do, the more likely we are to succeed,” Hothersall-Thomas said. 

Ironically, that statement applies just as well to today's attackers. 

The age of the "right IP address" is over 

For years, a common assumption in threat intelligence was that if you could fetch a page from the same country as the victim, you'd probably be able to see the attack. That's becoming less true. 

According to Liam Dalgarno, a senior software engineer with Netcraft, modern phishing campaigns increasingly evaluate multiple pieces of information simultaneously rather than relying on any individual signal. 

"It's no longer the case that you can just be like, 'Oh, can we just get a residential IP in this location, and it solves all the issues,'" he said. 

Instead, attackers look for consistency. 

If a visitor claims to be using an iPhone in Tokyo, does everything else support that story? Does the browser's fingerprint align? Is the screen resolution plausible? Does the device language match the region? Does browsing behavior resemble a real person? 

That's what makes modern cloaking fundamentally different from earlier generations of phishing infrastructure. 

The goal is no longer simply reaching a phishing page; it’s to convince the phishing page that you belong there, and then eventually being able to take it down. 

AI didn't invent these techniques, but it made them easier. 

Browser fingerprinting, geofencing, and device targeting aren’t new tactics for attackers. But they can more easily deploy these tactics at the same time. 

"With LLMs, generating a phishing site that does all of those rather than doing one thing, is far more common now,” Sam Barnes-Thornton, a software engineering team lead, said. 

A few years ago, a phishing kit might have relied on one or two filtering techniques. 

Today, attackers can combine browser fingerprinting, ISP filtering, referral validation, device checks, time-based activation, and geo-fencing into a single phishing workflow with relatively little effort. 

The individual techniques aren't necessarily more sophisticated, but there are more layers. And every new layer creates another opportunity to filter out security teams before they ever see the attack. 

Why Netcraft focuses on victims, not just infrastructure 

As attackers have added more filtering layers, the importance of victim emulation has only increased. Netcraft's phishing detection systems are designed around understanding attacks from the perspective of intended victims, rather than relying solely on traditional web scanning techniques. 

The challenge isn't just gathering more IP addresses or running more crawlers. Instead, defenders need to understand what conditions are most likely to reveal an attack in the first place. 

"We've got all the connections, cities and countries to fetch from. We're running real browsers at scale, and we know ahead-of-time which configurations are most likely to be effective for a given fetch. And that's all automatic,” Hothersall-Thomas said. 

That final piece is often overlooked. 

A lot of vendors can operate residential proxies or launch automated browsers. Far fewer have developed the logic needed to determine which browser, location, connection type, and behavior profile is most likely to surface a hidden attack. 

Netcraft's global fetching infrastructure is built around the same reality attackers are exploiting. Whether traffic is coming through residential connections, mobile networks, ISP-based infrastructure, or customer-hosted fetchers, the goal is the same: appear to attackers the way a legitimate victim would appear.  

The purpose of Netcraft's “Community Fetcher” program, for example, is explicitly to present requests as though they originate from an actual potential victim rather than an obvious security scanner. 

Participating customers and volunteers in the Community Fetcher program host small Netcraft-managed devices on their networks, allowing Netcraft to view phishing attacks from the same real-world internet connections that attackers expect their victims to use. 

This makes it easier for Netcraft to pinpoint where victims actually are. 

“An organization may be headquartered in one location but serve customers across many different regions,” Hothersall-Thomas said. “What matters isn't where the organization is based. It's where attackers expect to find victims." 

Defenders increasingly need visibility through the eyes of customers, not corporate headquarters. 

Most security bots still don't look human 

An independent anti-cloaking study that analyzed more than 20 threat intelligence and security scanning bots found that most security vendors remain surprisingly easy to identify. Many relied heavily on cloud-hosted infrastructure. Others presented only a limited set of browser profiles. Most failed to interact with websites the way users actually do. 

The report ranked Netcraft's bot highest overall, citing its combination of broad URL sourcing, residential connectivity, platform diversity, and human-like interaction. 

One finding stood out in particular: Netcraft was the only vendor that consistently submitted login forms during testing and one of only a handful capable of interacting with websites beyond basic page loading. 

An organization may be headquartered in one location but serve customers across many different regions. What matters isn't where the organization is based. It's where attackers expect to find victims.

— Charlie Hothersall-Thomas, Netcraft Director of Engineering

An organization may be headquartered in one location but serve customers across many different regions. What matters isn't where the organization is based. It's where attackers expect to find victims.

— Charlie Hothersall-Thomas, Netcraft Director of Engineering

That matters because many modern phishing workflows don't reveal their full attack chain until a user takes an action. 

If your detection platform stops at loading a page, it may never see what the victim eventually encounters. 

That distinction is becoming increasingly important as attackers continue investing in anti-detection capabilities. 

What happens next 

Attackers are becoming increasingly selective. Rather than exposing malicious content to anyone who visits a URL, they're carefully controlling who sees what and under what conditions. 

Defenders are increasingly faced with what amounts to a layered "Swiss cheese" problem, Dalgarno said. 

"They're checking for this device in this country with these properties at this time, and we've got to find that one common hole through all of those layers,” he said. 

Attackers are investing heavily in systems that identify genuine victims and exclude defenders. In response, defenders must increasingly recreate the conditions under which real victims experience an attack. 

And increasingly, the side that wins isn't the one with the most domains, the most crawlers, or even the most intelligence — it's the side that's better at blending in. 

What is phishing cloaking?

Phishing cloaking is a technique attackers use to hide phishing content from security researchers, automated scanners, and threat intelligence platforms while still displaying malicious pages to intended victims. Modern cloaking systems can evaluate factors such as IP address, location, browser characteristics, device settings, user behavior, and referral sources before deciding whether to show a phishing page.

What is browser fingerprinting in phishing attacks?

Browser fingerprinting is a method attackers use to collect information about a visitor's device, browser, operating system, screen resolution, language settings, and other characteristics. Phishing campaigns can use this information to determine whether a visitor resembles a legitimate target or a security researcher before serving malicious content.

How do modern phishing sites identify real victims?

Modern phishing sites often evaluate multiple signals simultaneously, including geographic location, device type, browser fingerprint, referral source, language settings, internet service provider, browsing behavior, and interaction patterns. Attackers use these signals to determine whether a visitor matches the profile of an intended target.

What is geofencing in phishing attacks?

Geofencing is a filtering technique that restricts access to phishing content based on a visitor's geographic location. Attackers use geofencing to ensure that only users in specific countries or regions can access a phishing page, making detection and takedown efforts more difficult.


Why do some phishing attacks only appear to certain users?

Attackers increasingly design phishing campaigns to appear only to users who meet specific criteria. A phishing page may only be visible to visitors using a particular device, originating from a specific location, arriving through a targeted SMS message, or exhibiting behavior associated with genuine victims.

Don't want to miss out on updates?

Don't want to miss out on updates?

Don't want to miss out on updates?

Join our mailing list for regular blog posts and case studies from Netcraft.