Wazza phishing kit evades bots to hit global banks

Threat intel firm ANY.RUN has identified Wazza, a new phishing kit that systematically targets banking, government and manufacturing organizations across the US, Europe and Australia.[1][2][6] Rather than sending every visitor straight to a fake login page, Wazza runs incoming traffic through layered routing and anti-bot filters before exposing an Adobe Document Cloud-themed device code prompt.[1][2][6] The campaigns, first observed in September 2026 and still active into October, show how phishing operators are turning their delivery infrastructure into a detection-evasion engine.[2][8][9]

Analysis of Wazza traffic shows victims landing on wildcard subdomains under the host boegl-krysl[.]eu, where an /api/wazza-config endpoint checks whether the request belongs to an active campaign.[1][7] If the hostname is approved, a separate service issues a per-client marker via cloud worker infrastructure, and an /api/mint-token call generates a short-lived signed session token tied to that visitor.[6][7][8] Only after token and browser telemetry are validated does the flow redirect through paths such as /r and /meline toward the final Adobe-branded Device Code phishing page.[1][6][7]

By front-loading campaign validation, client markers, session tokens and telemetry checks, Wazza is designed to screen out scanners, crawlers and generic security tools before they ever see the lure.[2][6][7] Security researchers note that the kit’s use of several intermediate services and redirects makes the initial URL far less informative, undermining static link analysis commonly used in email gateways and proxy filters.[1][3][6] ANY.RUN has even released a dedicated HTTP activity signature (SID: 84004715) to help defenders recognize Wazza’s routing pattern in network telemetry.[9]

The phishing page itself imitates Adobe Document Cloud branding and asks users to enter or approve a device code, targeting modern account authentication flows rather than only traditional passwords.[1][2][6] Reports from Europe and Australia suggest the lures are being used against Microsoft 365 users in financial institutions, manufacturers and government entities, where device code flows and approval prompts are familiar enough to lower suspicion.[6][7] Because the kit focuses on session and token theft within multi-factor authentication workflows, successful compromises can grant attackers persistent access to cloud accounts even when passwords are changed.[2][8]

So far, public reporting has not tied Wazza to a specific threat actor or commercial phishing-as-a-service platform, but its sophistication and geographic spread point toward operators with experience running large-scale credential theft operations.[1][2][7] Multiple incidents aggregated in September threat roundups show activity spanning US and EU organizations, with campaigns adapting infrastructure and domains over time to stay ahead of blocklists.[2][8][10] The emergence of kits like Wazza reinforces that phishing defense can no longer rely on spotting obviously malicious URLs or crude login clones alone.[1][3][6]

Defenders are urged to tune email and web security tools to flag unexpected device code prompts and document-themed authentication requests, and to correlate them with user reports of unusual sign-in approvals.[2][6] Security teams should monitor for traffic patterns consistent with Wazza’s campaign checks and short-lived tokens, and use sandboxing or detonation environments capable of following multi-stage redirects to the final phishing payload.[2][6][9] Organizations in banking, manufacturing and government sectors are also being advised to reinforce user training around cloud authentication flows and to treat any unsolicited device code or approval request as a potential phishing attempt.[2][6][7]

References

  1. Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
  2. any.run · major-cyber-attacks-september-2026Major Cyber Attacks in September 2026: US & EU Threats
  3. Threat Intelligence — Latest News, Reports & Analysis
  4. New Wazza Phishing Kit Screens Visitors Before Showing Its …
  5. Wazza colpisce banche e governi: phishing Microsoft 365 nascosto ai bot – Matrice Digitale
  6. Major Cyber Attacks in September 2026: US Organizations Face …
  7. ANY.RUN’s Threat Coverage Digest: September 2026
  8. news.mlab.sh: Cyber security headlines

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply