arrow_back Back to Blog
ATTACK ANALYSIS

Phishing Cloaking and Evasion: Why Standard CTI Tools Are Going Blind

By Tetik.NET Threat Labs · June 2, 2026

The financial cybercrime world has undergone a massive transformation in the last few years. We are no longer dealing with amateur scammers hosting fake websites on cheap servers. Today’s phishing infrastructures have evolved into military-grade Phishing-as-a-Service platforms that poison machine learning models, detect and evade Cyber Threat Intelligence (CTI) tools, and hunt in closed networks.

1. Research Traffic Detection via TLS Fingerprinting (JA3/JA4)

When a standard CTI tool scans a suspicious phishing site, it tries to hide by changing the User-Agent header to "iPhone 14". However, advanced panels (EvilProxy, Tycoon 2FA) do not fall for this trick. The encryption algorithms you present during the HTTPS handshake instantly expose you as a Python bot on a Linux server.

2. The Cloaking and Evasion Problem

The moment the attacker detects you as a bot, cloaking kicks in. While the real victim sees the banking login screen, your CTI bot sees a 404 Not Found or a blank page. When fake/clean data is fed into your Anti-Fraud AI models, your models are poisoned, making them victims of Adversarial Evasion.

3. Telegram Phishing and Sockpuppet Networks

Cybercrime syndicates have shifted their hunting grounds from Google to closed networks like Telegram. Sponsored messages like "Bank Fee Refund" are broadcast to channels with hundreds of thousands of members. Since Telegram has no proactive filtering, standard CTI platforms cannot access this ecosystem and remain completely blind.

4. Overlay Attacks and ATS

By abusing Android's Accessibility services, a fake window is drawn on the screen the moment the victim opens their banking app. With ATS (Automated Transfer System), the malware performs ghost transfers by reading SMS codes in the middle of the night—without the victim even noticing.

5. Solution: Blending In Among Real Users

The root cause of all these issues is the defense entering the field as a "bot". Tetik CTI blends in among real users and never triggers any cloaking systems. Attackers are now hunting bots—you can only catch them when you act like a real human. Stay alert, stay with Tetik!

Stop Manual Monitoring

Tetik.NET automates your entire threat intelligence workflow. Detect phishing domains in seconds, automate DMCA takedowns, and monitor the dark web 24/7.

Deploy Tetik Intelligence