Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.

ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.
The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.
The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection.
MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control.
ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.
The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets.
For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.
The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu , where the visitor is passed to /api/wazza-config .
That token is passed to check[.]boegl-krysl[.]eu , where Wazza validates the token and browser telemetry and filters unwanted traffic.
What happened
ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.
What changed
The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.
The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection.
Who is affected
MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control.
ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.
Why it matters
The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets.
For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.
Technical details
The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu , where the visitor is passed to /api/wazza-config .
That token is passed to check[.]boegl-krysl[.]eu , where Wazza validates the token and browser telemetry and filters unwanted traffic.
Wazza's immediate objective is to deliver an Adobe-themed Device Code phishing page, but the potential impact does not necessarily end with the first successful authentication.
Response
For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments.
Blocking one Wazza domain does not necessarily end the campaign.
What security teams should do
An analyst can investigate a Wazza URL, identify useful indicators, validate them, and make that intelligence available to the systems monitoring customer environments.
The strongest response to Wazza is not simply to block the domains associated with one campaign.
Attribution
The Hacker News: Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.