Back to Feed
Threat IntelligenceOct 8, 2026

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Wazza phishkit uses multi-stage routing to target banking, government, and manufacturing sectors in US, EU, and

Summary

A new phishing kit named Wazza has been identified, employing a multi-stage routing infrastructure to screen visitors and automated traffic before delivering its payload. This sophisticated approach makes initial detection more challenging for security teams. Wazza targets critical sectors like banking, government, and manufacturing across the US, EU, and Australia, utilizing an Adobe-themed Device Code phishing page to harvest credentials.

Full text

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia The Hacker NewsOct 08, 2026Web Security / Threat Intelligence Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page. For security teams, that makes Wazza more than another malicious URL. The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection. MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control. That uncertainty can translate directly into longer investigation times and unnecessary escalations. Wazza Uses Multi-Stage Routing to Hide Its Phishing Page Wazza does not send every visitor directly to its phishing page. Instead, the phishkit uses a multi-stage routing chain to determine which requests should reach the final payload. To see how this works in practice, let’s follow a Wazza analysis in ANY.RUN’s Interactive Sandbox. Wazza attack chain exposed in ANY.RUN’s Interactive Sandbox The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu, where the visitor is passed to /api/wazza-config. This endpoint checks whether the hostname belongs to an active campaign. Wildcard routing config and allowed campaign prefixes in the Wazza attack analysis The infrastructure then contacts beacon-surge-sync[...]workers[.]dev, which issues a client marker that can be used to correlate the visit. Next, /api/mint-token generates a short-lived signed session token. Short-lived signed token for the current session after detonating a Wazza sample That token is passed to check[.]boegl-krysl[.]eu, where Wazza validates the token and browser telemetry and filters unwanted traffic. A Wazza attack: Minted token passed into the anti-bot validation gate Only after these checks does the visitor continue through boegl-krysl[.]eu/r and /meline, eventually reaching the final Adobe-themed Device Code phishing page. Final stage of a Wazza attack: Adobe-themed Device Code phishing landing Using a recognizable service as the visual theme gives the final stage a familiar appearance, while the Device Code flow provides the attacker with a way to target account authentication rather than relying solely on conventional password harvesting. That makes the final lure only one component of a larger operation. The infrastructure first determines whether the visitor should be shown the phishing page. The social-engineering component comes afterward, once the campaign has established a session it considers suitable. This layered approach is important for defenders because a URL can appear relatively unremarkable until its behavior is reproduced in the right environment. Give your team the context to investigate phishing threats faster and ensure 30% less Tier 1 to Tier 2 escalations. Integrate ANY.RUN Wazza’s Reach Across Key Sectors: Government, Banking, and Manufacturing ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors. Regions and sectors targeted by Wazza These organizations operate high-value business processes and manage information that can be attractive to attackers. Financial institutions handle sensitive accounts and transactions, manufacturers depend on interconnected corporate environments and business systems, while government organizations manage sensitive information and critical services. But the campaign's relevance goes beyond those individual sectors. The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets. The final branding can change, while the underlying approach — filtering visitors, validating sessions, and selectively delivering the lure — remains useful to attackers. The Adobe theme also reflects how phishing operators continue to use familiar brands to make authentication requests appear routine. The branding may change, but the objective is consistent: persuade the victim to complete an authentication action that can provide an attacker with access to an account or session. Why Wazza Creates a Bigger Problem for MSSPs For an MSSP, an evasive phishing kit creates a different challenge from a straightforward malicious URL. The provider is not investigating a single environment. Analysts may be responsible for multiple customers, different security stacks, and large volumes of alerts, often while working against defined response and escalation requirements. Wazza adds uncertainty to that workflow. A suspicious URL may initially appear benign because the final phishing page is not immediately served. Automated security systems may receive different content from a human visitor. And an analyst who cannot reproduce the complete routing sequence may have to escalate the investigation simply to determine what the URL actually delivers. The result can be a familiar MSSP problem: more time spent investigating, more cases moving to senior analysts, and less capacity for genuinely complex incidents. This is why the ability to interact with suspicious content in an isolated environment matters. ANY.RUN's Interactive Sandbox allows analysts to open suspicious URLs using virtual machines that start in under 10 seconds, interact with the resulting pages, follow redirects, and observe network and behavioral activity. Wazza analyzed in ANY.RUN’s Interactive Sandbox Using the solutions, analysts can get comprehensive Tier 1 reports in around 40 seconds, IOCs, screenshots, process graphs, and MITRE ATT&CK mapping. For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources. One Wazza Investigation Can Reveal More Than One IOC The infrastructure behind Wazza should not be viewed simply as a list of domains to block. Its multi-stage routing creates several intelligence pivots. An analyst can start with one suspicious URL and uncover additional domains, endpoints, redirect paths, and behavioral indicators linked to the campaign. ANY.RUN Threat Intelligence Lookup (TI Lookup) provides another way to investigate these connections. Analysts can pivot from IOCs to related threat activity and use query updates to track changes over time. Searching for Wazza in ANY.RUN’s TI Lookup For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments. This helps analysts identify connections even when attackers change individual indicators but retain elements of the same campaign. Continuous Threat Intelligence Turns Findings into Ongoing Monitoring Blocking one Wazza domain does not necessarily end the campaign. Phishing infrastructure can change, domains can be replaced, and routing logic can be modified as attackers adapt to detection. A static IOC list therefore has a limited lifespan. ANY.RUN Threat Intelligence Feeds (TI Feeds) are designed to turn IOCs into continuous monitoring by streaming 99% unique, validated indicators and behavior-based threat data into security environments. The solutioon also supports STIX/TAXII, API, and SDK, allowing intelligence to be incorporated into existing security workflows. ANY.RUN’s real-time threat intelligence feeds with near-zero f

Indicators of Compromise

  • domain — boegl-krysl.eu
  • domain — beacon-surge-sync.workers.dev

Entities

Device Code (product)Phishing (technology)