Cloaking Malware Fools Security Scanners by Showing Clean Pages to Bots

A sophisticated malware campaign discovered in early 2026 used cloaking technology to serve harmless pages to security scanners while delivering malicious content to real users. The attack was uncovered after authenticated Carnival Cruise Line marketing emails routed genuine customers to malware installers and browser hijackers. The malicious landing page fingerprinted each visitor and made real-time decisions on what to display, meaning every reputation engine that checked the link returned a clean verdict for months. Security researcher Daniel Jones of Tuxxin LLC found the redirection layer, dubbed PseudoTDS, and the browser-hijacker family PhantomJack — both originally named by Trinity Cyber in a November 2025 report. The case highlights a fundamental flaw in single-point URL scanning, where a clean result reflects only what one scanner saw at one moment, not the true nature of the link.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in