Security researchers at ANY.RUN have discovered a new and sophisticated phishing kit named Wazza. This kit is being used in campaigns targeting a wide range of sectors, including banking, manufacturing, and government, with victims identified in the United States, Europe, and Australia. The Wazza phishkit distinguishes itself with advanced evasion capabilities, primarily a multi-stage routing infrastructure designed to filter out automated analysis systems. By weeding out security scanners and sandboxes, the attackers ensure their final phishing page is only presented to legitimate human targets, significantly increasing the campaign's effectiveness and complicating detection efforts for security teams.
The Wazza phishing campaign begins with a standard phishing email. However, the link within the email does not lead directly to the final phishing page. Instead, it directs the victim into a multi-stage routing chain. Each stage in this chain performs checks on the visitor to determine if they are a human using a standard browser or an automated tool.
This routing and filtering mechanism is the core of the kit's sophistication. It is designed to identify and block:
If a visitor is flagged as non-human or suspicious, they are redirected to a benign page or a dead end. Only visitors who pass all checks are routed to the final malicious payload: an Adobe-themed Device Code phishing page. This type of page is designed to trick the user into authorizing a malicious application to access their account, a technique often used to bypass MFA.
The multi-stage architecture provides several advantages to the attacker:
The infrastructure itself, with its multiple domains and endpoints used in the routing chain, provides defenders with additional indicators of compromise (IOCs) if they can successfully trace it.
T1566.002 - Spearphishing Link: The initial access vector is a link delivered via email.T1598.002 - Spearphishing Link: The multi-stage routing chain is a form of defense evasion that makes the link appear benign to automated systems.T1078 - Valid Accounts: The ultimate goal of the campaign is to trick users into providing credentials or authorizing device codes to take over their accounts.T1649 - Steal or Forge Authentication Tokens: Device Code phishing is specifically designed to steal authentication tokens.The Wazza phishkit poses a significant threat due to its ability to bypass common automated security defenses. This leads to a higher success rate for the phishing emails that reach user inboxes. For the targeted sectors—banking, manufacturing, and government—a successful attack could lead to financial theft, data breaches, and compromise of sensitive government systems. The increased workload on security operations centers (SOCs) and Managed Security Service Providers (MSSPs) is also a notable impact. Analysts must spend more time on each phishing alert, which can lead to burnout and slower response times across the board.
No specific indicators of compromise were provided in the source articles.
To detect multi-stage phishing like the Wazza kit, analysts should look for:
Web Proxy / DNS LogsDetection:
D3-DA: Dynamic Analysis)D3-UA: URL Analysis)Response:
Train users to be cautious of emails prompting for login, especially those involving device codes or unexpected authorizations.
While device code phishing can bypass some MFA, using phishing-resistant authenticators like FIDO2 keys is the most effective defense.
Employ web filtering solutions with click-time protection and the ability to analyze URLs in-depth to uncover redirection chains.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.