thehackernews.com 8 Oct 2026, 10:30 UTC

Wazza Phishing Kit Hides Adobe Lures Behind a Multi-Stage Trap

ANY [.]RUN has tracked a new phishing kit named Wazza that targets banking, manufacturing, and government organisations across the US, Europe and Australia. Unlike traditional credential theft kits, Wazza employs a multi-stage routing chain to decide which requests reach the final lure, making the initial link appear less informative and complicating automated detection. The final lure is an Adobe-themed Device Code phishing page, designed to capture authentication actions rather than simple password harvesting.

The campaign is presented as a layered delivery system, with social engineering triggered only after a session has been established, emphasising that the phishing page is only one component of a broader operation.

The analysis shows how Wazza operates: a wildcard landing domain funnels visitors to an API that checks campaign validity, then a beaconing stage issues a client marker and a short‑lived signed session token, which must pass a series of anti‑bot and telemetry checks before reaching the phishing page. This approach allows attackers to filter traffic, validate sessions and selectively deliver the lure.

Evidence from ANY[.]RUN’s interactive sandbox and threat intelligence tooling demonstrates how MSSPs and security teams can pivot from one suspicious URL to a larger map of domains, endpoints and behaviours associated with the campaign. The article highlights practical responses: detonate suspicious URLs in isolated sandboxes for context, use TI Lookups to connect IOCs, and deploy continuous threat intelligence feeds to monitor evolving infrastructure and protect multiple customer environments.

View full article

Article by CyberSIXT