Wazza Phishkit Targets Banking and Government

New 'Wazza' Phishkit Uses Advanced Evasion to Target Global Orgs

MEDIUM
October 8, 2026
5m read
PhishingMalware

Related Entities

Organizations

ANY.RUNAdobe

Other

Wazza

Full Report

Executive Summary

Security researchers at ANY.RUN have discovered a new and sophisticated phishing kit named Wazza. This kit is being used in campaigns targeting a wide range of sectors, including banking, manufacturing, and government, with victims identified in the United States, Europe, and Australia. The Wazza phishkit distinguishes itself with advanced evasion capabilities, primarily a multi-stage routing infrastructure designed to filter out automated analysis systems. By weeding out security scanners and sandboxes, the attackers ensure their final phishing page is only presented to legitimate human targets, significantly increasing the campaign's effectiveness and complicating detection efforts for security teams.

Threat Overview

The Wazza phishing campaign begins with a standard phishing email. However, the link within the email does not lead directly to the final phishing page. Instead, it directs the victim into a multi-stage routing chain. Each stage in this chain performs checks on the visitor to determine if they are a human using a standard browser or an automated tool.

Evasion and Filtering

This routing and filtering mechanism is the core of the kit's sophistication. It is designed to identify and block:

  • Security vendor crawlers
  • Automated sandboxes
  • Traffic from VPNs or datacenter IP ranges
  • Non-standard user agents

If a visitor is flagged as non-human or suspicious, they are redirected to a benign page or a dead end. Only visitors who pass all checks are routed to the final malicious payload: an Adobe-themed Device Code phishing page. This type of page is designed to trick the user into authorizing a malicious application to access their account, a technique often used to bypass MFA.

Technical Analysis

The multi-stage architecture provides several advantages to the attacker:

  1. Evasion: It effectively hides the final phishing page from security tools, preventing the malicious domain from being quickly blocklisted.
  2. Longevity: By evading detection, the phishing infrastructure can remain operational for longer periods.
  3. Analyst Frustration: It significantly increases the time and effort required for security analysts to investigate an alert. An analyst or an automated tool visiting the initial link will not see the malicious content, potentially leading them to dismiss the alert as a false positive. Manual, careful reproduction of a real user's environment is required to trace the full attack chain.

The infrastructure itself, with its multiple domains and endpoints used in the routing chain, provides defenders with additional indicators of compromise (IOCs) if they can successfully trace it.

MITRE ATT&CK Techniques

Impact Assessment

The Wazza phishkit poses a significant threat due to its ability to bypass common automated security defenses. This leads to a higher success rate for the phishing emails that reach user inboxes. For the targeted sectors—banking, manufacturing, and government—a successful attack could lead to financial theft, data breaches, and compromise of sensitive government systems. The increased workload on security operations centers (SOCs) and Managed Security Service Providers (MSSPs) is also a notable impact. Analysts must spend more time on each phishing alert, which can lead to burnout and slower response times across the board.

IOCs — Directly from Articles

No specific indicators of compromise were provided in the source articles.

Cyber Observables — Hunting Hints

To detect multi-stage phishing like the Wazza kit, analysts should look for:

Type
URL Pattern
Value
Multiple rapid HTTP redirects (301/302)
Description
A chain of redirects originating from an email link is a common pattern for this type of evasion.
Type
Log Source
Value
Web Proxy / DNS Logs
Description
Correlate email link clicks with subsequent DNS queries and web requests to identify the full redirection chain.
Type
URL Pattern
Value
URLs containing long, randomized query strings
Description
These are often used as session identifiers to track a victim through the filtering stages.
Type
Other
Value
Discrepancy in content
Description
A discrepancy between what an automated sandbox sees and what is reported by a user is a strong indicator of an evasive threat.

Detection & Response

Detection:

  1. Advanced Email Security: Use email security gateways with sandboxing capabilities that can attempt to mimic real user behavior to follow redirection chains. (D3FEND: D3-DA: Dynamic Analysis)
  2. Browser Isolation: Remote Browser Isolation (RBI) technology can render the phishing site in a remote, disposable container, protecting the user from the malicious content regardless of evasion.
  3. URL Analysis at Click-Time: Utilize security solutions that re-evaluate the URL's reputation at the time of the user's click, rather than just at the time of email delivery. (D3FEND: D3-UA: URL Analysis)

Response:

  1. Block Infrastructure: Once the full redirection chain is identified, block all associated domains and IPs at the firewall and web filter.
  2. User Account Reset: If a user has interacted with the final phishing page, assume their account is compromised. Revoke active sessions and force a password reset.
  3. Hunt for Similar IOCs: Use the identified domains and IPs to hunt for other potential victims within the organization.

Mitigation

  • User Training: Continuously train users to be suspicious of unexpected emails, especially those prompting for login or device authorization. Emphasize that even legitimate-looking services like Adobe can be impersonated.
  • Phishing-Resistant MFA: Implement FIDO2/WebAuthn as it is resistant to most forms of phishing, including credential and token theft.
  • Restrict OAuth Applications: Configure identity providers to block users from consenting to new or unverified third-party applications, which is a common goal of Device Code phishing.

Timeline of Events

1
October 8, 2026
This article was published

MITRE ATT&CK Mitigations

Train users to be cautious of emails prompting for login, especially those involving device codes or unexpected authorizations.

While device code phishing can bypass some MFA, using phishing-resistant authenticators like FIDO2 keys is the most effective defense.

Employ web filtering solutions with click-time protection and the ability to analyze URLs in-depth to uncover redirection chains.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

phishingwazzaphishkitevasionany.rundevice code

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.