AI threat detection · iOS, Mac, Android

Phone security that catches zero-day phishing in under 90 seconds

Casper's Cloak runs a real machine-learning classifier on every domain your devices try to reach — blocking phishing sites, malware command-and-control, credential exfiltration, and scam storefronts before they're on any public blocklist. Works in every app, not just your browser. Same protection on hostile public WiFi.

<90 s
Median time-to-block, zero-day phishing
<0.05%
False-positive rate on Tranco 1M
Every app
SMS, iMessage, email, browsers, webviews
Public WiFi
Encrypted on hostile networks

What Casper actually blocks

Not a marketing layer over a blocklist. A real ML classifier, scoring every DNS query in milliseconds against ~40 features.

Phishing sites — including zero-day

The fake bank-login, fake Apple ID, fake delivery-tracker pages that arrive via SMS, iMessage, email, or WhatsApp. Caught by the AI model before the site is reported anywhere public.

Malware command-and-control

If an app on your phone is compromised, it can't reach its C2 server through Casper. The damage stays bounded; data doesn't leave the device.

Scam storefronts + crypto drains

Fake e-commerce sites, cryptocurrency drain pages, romance-scam infrastructure, fake-investment portals. Real-time scoring of newly-registered hostile domains.

Public-WiFi attacks

Encrypted VPN tunnel hides your traffic from coffee-shop networks, hotel WiFi, airport WiFi. No script injection, no TLS man-in-the-middle.

Credential exfiltration

When a malicious app or page tries to ship your passwords / cookies / tokens to an attacker-controlled endpoint, the connection is refused at the DNS layer.

Zero-day, not just known-bad

Pure blocklists react to threats. The AI model scores domains by their structural features (registration age, naming patterns, TLS signatures) — so brand-new threats get caught the first time anyone reaches them.

How AI threat detection actually works

Every DNS query your phone makes runs through a classifier in milliseconds. Here's what it's looking at.

1

Your device tries to reach a hostname

Could be from any app — Safari, Messages opening an SMS link, the email client, a webview embedded in a free game. All app traffic routes through Casper.

2

Model scores the hostname in ~3 ms

Features: domain age, registrar, TLS cert chain + age, DNS topology, hostname-to-brand similarity (Levenshtein-distance from popular brands), cluster proximity to known-bad infrastructure, presence of common phishing keywords, IP autonomous-system reputation, ~40 features total. Output: 0.0–1.0 risk score.

3

Decision in real time

Score above the threshold → block with a clear warning page. Score in the gray zone → log + allow + flag for review. Score below threshold → resolve normally. No perceptible latency to you.

4

Feedback loops back into the model

False-positive overrides (when a user marks a block as wrong) and aggregate behavior (sites being looked up from many devices then immediately abandoned) flow back into retraining within ~24 hours. The model gets sharper with use.

Net effect

Zero-day phishing — the kind that ships out via SMS at 2 AM and is gone by morning — gets caught within seconds of you tapping the link, not days later when a blocklist catches up. Same protection on every app, not just your browser.

Threat-protection FAQs

What security-conscious users ask first.

Casper's threat detection runs a real machine-learning classifier on the domains your devices try to reach. The model is trained on millions of labeled examples — known phishing sites, malware command-and-control servers, scam storefronts, malvertising infrastructure, exfiltration endpoints. When your device tries to resolve a hostname (even one we've never seen before), the model scores it in milliseconds based on registration age, TLS cert patterns, DNS topology, naming structure, similarity to known-bad clusters, and ~40 other features. High-risk scores get blocked. Pure blocklists alone can't catch zero-day phishing — the AI layer is what closes that gap.

Catch the next phishing link before you tap it.

Free trial. iOS, Mac, and Android. Real-time AI threat scoring on every connection — including hostile public WiFi.