Join our Newsletter — 33% off our NHI Course

Conditional Delivery

Conditional delivery is a malicious technique where a page or payload changes behavior based on context, such as referrer, browser, or source engine. Attackers use it to hide malicious content from casual inspection and to show different responses to security researchers, direct visits, or search traffic.

What Conditional Delivery Means in Attack Traffic

Conditional delivery is not a payload type by itself, but a delivery pattern. The malicious page or script inspects context, then changes what it shows, when it executes, or whether it serves the payload at all. That context can include the referrer, source IP, browser fingerprint, language, device type, or whether the visit looks automated.

This makes the technique useful for hiding malicious behavior during casual review. A link scanner, sandbox, analyst browser, or search-engine crawl may receive harmless content, while the intended victim sees the exploit, lure, or redirect chain. The core idea is selective exposure, not a unique exploit primitive.

How Conditional Delivery Hides Malicious Content

Conditional delivery works by placing logic in the page, redirect chain, or server response that evaluates the visitor before deciding what to return. Attackers may use simple branching, scripts that read browser properties, or server-side rules that suppress malicious output unless the request matches a target profile.

In practice, the technique can delay execution, serve benign filler, or present a different page to security tooling. This frustrates static analysis because the artifact that gets reviewed is not always the artifact a victim receives. It also complicates incident triage because the observed content may change depending on who is checking it.

Where Conditional Delivery Shows Up

Conditional delivery appears in phishing pages, drive-by delivery chains, malvertising, and traffic-filtered payload staging. It is especially common when attackers want to reduce visibility during scanning or when they are tailoring content to a narrow target set.

The technique may be implemented with redirects, JavaScript checks, fingerprinting, or server-side gating. It can also be paired with time-based logic, so the page behaves differently after a delay or only after a first benign request. That makes reproduction harder and can give defenders a false sense of safety if they test the wrong path.

Because the behavior depends on request context, security teams often need to compare multiple fetch paths, user agents, and network vantage points. Tooling that only captures one version of a page may miss the malicious branch entirely.

Defensive Implications of Context-Sensitive Delivery

For defenders, the main challenge is that conditional delivery weakens trust in a single observation. A page that looks harmless in a sandbox may still be malicious for a real user, so analysis should consider alternate responses, header and referrer manipulation, and browser emulation rather than relying on one fetch.

Detection is stronger when analysts look for response variance, unusual redirect logic, and content that changes with automation signals. Network telemetry, URL inspection, and browser-level observation all help, because each can expose a different branch of the same delivery flow.

Risk and Threat Considerations

Conditional delivery raises the risk that malicious content will evade inspection long enough to reach a target. It is particularly effective against automated systems that expect consistent responses, because the attacker can withhold the harmful branch until the request looks like a real user session.

Failure mechanism: The attacker uses request-aware logic to separate benign inspection traffic from victim traffic, which reduces the chance that scanning, crawling, or manual review will reveal the malicious payload.

Impact: Defenders may miss phishing pages, exploit chains, or redirect infrastructure until after exposure has already occurred, increasing the chance of successful compromise and slowing containment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while OWASP ASVS sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1036 — Masquerading Conditional delivery disguises malicious content behind benign-looking responses.
T1204 — User Execution Conditional delivery often waits for a real user interaction before exposing malicious content.
T1189 — Drive-by Compromise The technique is commonly used to gate malicious content in web delivery chains.
Recommendation — Map response variance to masquerading and test alternate delivery paths in analysis. Trace lure-dependent branches and validate whether user interaction triggers payload delivery. Inspect web delivery chains for conditional branches that hide exploit content from scanners.
OWASP ASVS V16 — Security Logging and Error Handling Consistent logging helps reveal request-path differences used by conditional delivery.
V15 — Secure Coding and Architecture Server and client logic that branches on request context is a secure-design concern.
Recommendation — Log request context and response variance to surface context-sensitive delivery behavior. Review delivery logic for hidden branches that alter content based on request attributes.

Practitioner Guidance

What to watch for: Treat inconsistent page behavior as a signal, not a nuisance. If a URL returns different content based on browser, referrer, or source network, examine the delivery logic as part of the threat, not just the visible page.

Practitioner takeaway: The safest assumption is that one sample is not enough. Conditional delivery is designed to make the first look harmless, so validation should focus on repeatable testing across contexts rather than a single observed response.