DKDKCISSPSearch
Cyber Attacks

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.

DKCISSP News DeskThe Hacker News8 Oct 2026, 4:00 pm
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.

The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.

The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection.

MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control.

ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.

The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets.

For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.

The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu , where the visitor is passed to /api/wazza-config .

That token is passed to check[.]boegl-krysl[.]eu , where Wazza validates the token and browser telemetry and filters unwanted traffic.

What happened

ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.

What changed

The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.

The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection.

Who is affected

MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control.

ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.

Why it matters

The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets.

For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.

Technical details

The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu , where the visitor is passed to /api/wazza-config .

That token is passed to check[.]boegl-krysl[.]eu , where Wazza validates the token and browser telemetry and filters unwanted traffic.

Wazza's immediate objective is to deliver an Adobe-themed Device Code phishing page, but the potential impact does not necessarily end with the first successful authentication.

Response

For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments.

Blocking one Wazza domain does not necessarily end the campaign.

What security teams should do

An analyst can investigate a Wazza URL, identify useful indicators, validate them, and make that intelligence available to the systems monitoring customer environments.

The strongest response to Wazza is not simply to block the domains associated with one campaign.

Attribution

The Hacker News: Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google DomainsThe Hacker News · 8 Oct 2026, 12:18 amWikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesThe Hacker News · 7 Oct 2026, 8:28 pmPhishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs | HuntressHuntress · 7 Oct 2026, 6:30 pmAttackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix LuresThe Hacker News · 30 Sept 2026, 9:22 pm