ANY [.]RUN has tracked a new phishing kit named Wazza that targets banking, manufacturing, and government organisations across the US, Europe and Australia. Unlike traditional credential theft kits, Wazza employs a multi-stage routing chain to decide which requests reach the final lure, making the initial link appear less informative and complicating automated detection. The final lure is an Adobe-themed Device Code phishing page, designed to capture authentication actions rather than simple password harvesting.
The campaign is presented as a layered delivery system, with social engineering triggered only after a session has been established, emphasising that the phishing page is only one component of a broader operation.
The analysis shows how Wazza operates: a wildcard landing domain funnels visitors to an API that checks campaign validity, then a beaconing stage issues a client marker and a short‑lived signed session token, which must pass a series of anti‑bot and telemetry checks before reaching the phishing page. This approach allows attackers to filter traffic, validate sessions and selectively deliver the lure.
Evidence from ANY[.]RUN’s interactive sandbox and threat intelligence tooling demonstrates how MSSPs and security teams can pivot from one suspicious URL to a larger map of domains, endpoints and behaviours associated with the campaign. The article highlights practical responses: detonate suspicious URLs in isolated sandboxes for context, use TI Lookups to connect IOCs, and deploy continuous threat intelligence feeds to monitor evolving infrastructure and protect multiple customer environments.