- It's called "User Agent staining" - "Each stain is visible in passively collected SIGINT and is stamped into every packet, which enables all the events from that stained machine to be brought back together to recreate a browsing session."
I'm wondering if they're not staining the browser user-agent string itself, but somehow modifying another part of the browser fingerprint (e.g., any of the things listed at https://panopticlick.eff.org/index.php?action=log&js=yes). If it's in "every packet", it would have to be a piece of info that is always sent by the browser.