A phishing pattern in which the same URL presents different content to scanners and real users. This creates a governance blind spot because automated analysis may report the link as benign while the victim is routed to the live malicious destination.
How split-view phishing works
Split-view phishing is a cloaking pattern, the attacker serves one version of a page to automated scanners and a different version to real visitors. The scanner sees a benign or empty page, while the user receives the active phishing flow.
This matters because the attacker is not merely hiding a link behind a short-lived redirect. The page itself becomes conditional, with content selection based on signals such as user agent, IP reputation, JavaScript execution, cookies, or other request features.
Why scanners miss it
Security tooling often evaluates a page in a controlled, non-interactive way, which makes it easier for split-view logic to return a safe decoy. That is why the same URL can appear harmless during detonation or reputation checks, yet still deliver credential harvesting, malware, or consent abuse to a live browser.
The weakness is a visibility gap, not a lack of malicious intent. The adversary is exploiting the difference between automated inspection conditions and the conditions under which a human victim actually loads the page. EmeraldWhale Git config credential theft shows how exposed configuration and credential material can support broader phishing-related abuse.
Where split-view phishing fits in the attack chain
Split-view logic is commonly used as an initial access control, helping the attacker preserve infrastructure reputation and delay takedown. It can also support payload staging, consent phishing, fake login pages, or token theft after the first request has passed whatever screening exists.
Because the malicious destination is only exposed selectively, defenders may undercount the campaign’s scope or misclassify it as low risk. CoPhish OAuth phishing via Copilot Studio is a useful reference point for phishing flows that pivot into token theft, while Mailchimp breach 2022 illustrates how social engineering can be paired with credential and API-key abuse.
Detection and defensive implications
Split-view phishing is hardest to catch when analysis assumes one fetch is enough. Defenders need to treat the URL as a stateful target, where the response can vary across time, client profile, and environment. That makes single-pass reputation checks, simplistic sandboxing, and static screenshot review unreliable on their own.
More resilient review comes from comparing responses across multiple fetch conditions and looking for mismatches in HTML, scripts, redirects, and downstream destinations. NIST SP 800-63 Digital Identity Guidelines is relevant when the phishing flow aims to defeat authentication assurance, and NIST Privacy Framework helps frame the exposure of user data that may result from successful credential capture.
Risk and Threat Considerations
Split-view phishing creates a direct detection gap, because the security control that inspects the page may be shown a harmless variant while the user receives the malicious one. That can suppress warnings, delay response, and let the campaign persist longer than a conventional phishing site.
Failure mechanism: The attacker conditions the response on scanner-facing traits, so automated analysis records a benign page while the live browser is redirected to the phishing payload, fake login, or token-theft flow.
Impact: The result is higher likelihood of credential theft, session compromise, consent abuse, or malware delivery, plus slower takedown and weaker incident visibility.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Split-view phishing exploits inspection gaps that audit and analysis controls are meant to surface. |
| SI-4 — System Monitoring | Monitoring controls are needed to detect conditional responses and phishing delivery changes. | |
| SC-7 — Boundary Protection | The technique abuses trust boundaries between inspection tools and live users. | |
| Recommendation — Correlate fetch differences and investigate inconsistent page behavior as suspicious activity. Monitor URL behavior across client contexts and alert on content that changes by scanner or user profile. Enforce inspection at boundaries and compare request paths before allowing sensitive destinations. | ||
| MITRE ATT&CK | T1566 — Phishing | Split-view phishing is a phishing delivery pattern that hides malicious content from defenders. |
| Recommendation — Map split-view delivery to phishing detections and hunt for conditional web responses. | ||
| OWASP API Security Top 10 | API8 — Security Misconfiguration | Conditional page behavior can exploit weakly validated or inconsistently exposed web surfaces. |
| Recommendation — Review web delivery controls for inconsistent responses and remove environment-based content gating. | ||
Practitioner Guidance
What to watch for: Treat inconsistent page behavior as a signal, especially when a URL changes content by client, geography, time, or execution context. A single clean scan should not be considered proof of safety when the page participates in login, consent, or payment flows.
Practitioner note: The most useful control is skepticism about one-dimensional verdicts. Where a URL is sensitive, confirm it under multiple fetch conditions and preserve the response artifacts so analysts can compare what the scanner saw with what a real user would see.