Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself.

ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.

For security teams, that makes Wazza more than another malicious URL. The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection.

MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control. That uncertainty can translate directly into longer investigation times and unnecessary escalations.

Wazza Uses Multi-Stage Routing to Hide Its Phishing Page

Wazza does not send every visitor directly to its phishing page. Instead, the phishkit uses a multi-stage routing chain to determine which requests should reach the final payload.

To see how this works in practice, let’s follow a Wazza analysis in ANY.RUN’s Interactive Sandbox.

Wazza attack chain exposed in ANY.RUN’s Interactive Sandbox

The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu, where the visitor is passed to /api/wazza-config. This endpoint checks whether the hostname belongs to an active campaign.

Wildcard routing config and allowed campaign prefixes in the Wazza attack analysis

The infrastructure then contacts beacon-surge-sync[...]workers[.]dev, which issues a client marker that can be used to correlate the visit. Next, /api/mint-token generates a short-lived signed session token.

Short-lived signed token for the current session after detonating a Wazza sample

That token is passed to check[.]boegl-krysl[.]eu, where Wazza validates the token and browser telemetry and filters unwanted traffic.

A Wazza attack: Minted token passed into the anti-bot validation gate

Only after these checks does the visitor continue through boegl-krysl[.]eu/r and /meline, eventually reaching the final Adobe-themed Device Code phishing page.

Final stage of a Wazza attack: Adobe-themed Device Code phishing landing

Using a recognizable service as the visual theme gives the final stage a familiar appearance, while the Device Code flow provides the attacker with a way to target account authentication rather than relying solely on conventional password harvesting.

That makes the final lure only one component of a larger operation. The infrastructure first determines whether the visitor should be shown the phishing page. The social-engineering component comes afterward, once the campaign has established a session it considers suitable.

This layered approach is important for defenders because a URL can appear relatively unremarkable until its behavior is reproduced in the right environment.

Give your team the context to investigate phishing threats faster and ensure 30% less Tier 1 to Tier 2 escalations.

Integrate ANY.RUN

Wazza’s Reach Across Key Sectors: Government, Banking, and Manufacturing

ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.

Regions and sectors targeted by Wazza

These organizations operate high-value business processes and manage information that can be attractive to attackers. Financial institutions handle sensitive accounts and transactions, manufacturers depend on interconnected corporate environments and business systems, while government organizations manage sensitive information and critical services.

But the campaign's relevance goes beyond those individual sectors. The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets. The final branding can change, while the underlying approach — filtering visitors, validating sessions, and selectively delivering the lure — remains useful to attackers.

The Adobe theme also reflects how phishing operators continue to use familiar brands to make authentication requests appear routine.

The branding may change, but the objective is consistent: persuade the victim to complete an authentication action that can provide an attacker with access to an account or session.

Why Wazza Creates a Bigger Problem for MSSPs

For an MSSP, an evasive phishing kit creates a different challenge from a straightforward malicious URL.

The provider is not investigating a single environment. Analysts may be responsible for multiple customers, different security stacks, and large volumes of alerts, often while working against defined response and escalation requirements.

Wazza adds uncertainty to that workflow. A suspicious URL may initially appear benign because the final phishing page is not immediately served. Automated security systems may receive different content from a human visitor. And an analyst who cannot reproduce the complete routing sequence may have to escalate the investigation simply to determine what the URL actually delivers.

The result can be a familiar MSSP problem: more time spent investigating, more cases moving to senior analysts, and less capacity for genuinely complex incidents.

This is why the ability to interact with suspicious content in an isolated environment matters.

ANY.RUN's Interactive Sandbox allows analysts to open suspicious URLs using virtual machines that start in under 10 seconds, interact with the resulting pages, follow redirects, and observe network and behavioral activity. 

Wazza analyzed in ANY.RUN’s Interactive Sandbox

Using the solutions, analysts can get comprehensive Tier 1 reports in around 40 seconds, IOCs, screenshots, process graphs, and MITRE ATT&CK mapping.

For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.

One Wazza Investigation Can Reveal More Than One IOC

The infrastructure behind Wazza should not be viewed simply as a list of domains to block.

Its multi-stage routing creates several intelligence pivots. An analyst can start with one suspicious URL and uncover additional domains, endpoints, redirect paths, and behavioral indicators linked to the campaign.

ANY.RUN Threat Intelligence Lookup (TI Lookup) provides another way to investigate these connections. Analysts can pivot from IOCs to related threat activity and use query updates to track changes over time.

Searching for Wazza in ANY.RUN’s TI Lookup

For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments. This helps analysts identify connections even when attackers change individual indicators but retain elements of the same campaign.

Continuous Threat Intelligence Turns Findings into Ongoing Monitoring

Blocking one Wazza domain does not necessarily end the campaign. Phishing infrastructure can change, domains can be replaced, and routing logic can be modified as attackers adapt to detection. A static IOC list therefore has a limited lifespan.

ANY.RUN Threat Intelligence Feeds (TI Feeds) are designed to turn IOCs into continuous monitoring by streaming 99% unique, validated indicators and behavior-based threat data into security environments. The solutioon also supports STIX/TAXII, API, and SDK, allowing intelligence to be incorporated into existing security workflows.

ANY.RUN’s real-time threat intelligence feeds with near-zero false positives

Scale is the key advantage for an MSSP. An analyst can investigate a Wazza URL, identify useful indicators, validate them, and make that intelligence available to the systems monitoring customer environments. The provider does not need to manually repeat the same research for every customer that may be exposed.

The investigation effectively becomes a source of reusable detection intelligence.

Up to 58% more threats identified. Expand your threat coverage with fresh, high-confidence intelligence.

Explore TI Feeds

Using Integrations to Bring Intelligence into Security Workflows

Threat intelligence is most useful when it reaches the systems that analysts already use for detection and response.

ANY.RUN provides integrations with platforms including Microsoft Sentinel, Microsoft Defender, Splunk, Cortex XSOAR, IBM QRadar, MISP, TheHive, ThreatConnect, Tines, Torq, and others.

Use integrations to connect ANY.RUN to your security stack for unified protection

For MSSPs, this is an important part of the workflow because security providers already have established processes for collecting alerts, enriching investigations, and triggering response actions.

The objective is not to create another isolated source of intelligence that analysts must check manually. That allows the outcome of one investigation to contribute to protection across the wider SOC.

The Potential Impact of a Wazza Phishing Attack

Wazza's immediate objective is to deliver an Adobe-themed Device Code phishing page, but the potential impact does not necessarily end with the first successful authentication.

Potential outcomes include:

  • Account compromise: A successful Device Code phishing flow can give attackers access to targeted accounts or sessions.
  • Trusted identity abuse: A compromised account can provide a trusted identity for communicating with colleagues, partners, or customers.
  • Follow-on phishing: Attackers can potentially use compromised business identities to launch additional phishing attempts.
  • Infrastructure discovery: The routing chain provides additional domains, endpoints, and behavioral indicators that can help defenders understand the wider campaign.
  • Increased response effort: When the malicious behavior is hidden behind multiple checks, reproducing the attack and establishing its scope can require additional analyst time.

The key distinction is that Wazza is not simply a phishing landing page. Its infrastructure is designed to control who reaches the lure and under what conditions, adding an evasive layer before the social-engineering component of the attack.

Turning Wazza Investigations into Scalable Protection

The strongest response to Wazza is not simply to block the domains associated with one campaign. The investigation can become the starting point for a repeatable process that turns individual findings into broader protection.

A suspicious URL can be detonated in an interactive sandbox to expose its behavior, giving Tier 1 analysts the context needed to make a decision without automatically escalating the case. Relevant IOCs can then be investigated through Threat Intelligence Lookup to identify associated activity.

Threat Intelligence Feeds can take those findings further by turning validated indicators into continuously updated intelligence. Instead of relying on a single block, MSSPs can use fresh threat data to help protect multiple customer environments as the campaign evolves.

The result is a workflow that moves from investigation to intelligence to protection, rather than ending when a single malicious URL is blocked.

That distinction matters for MSSPs because the scale of the problem is not defined by how many phishing URLs an analyst can investigate individually. It is defined by how much useful intelligence the team can extract from each investigation and how efficiently that intelligence can be applied across the customer base.

Cut 21 minutes from MTTR and help your MSSP team respond to client threats faster.

Accelerate Your MSSP Response

Wazza Shows Why the Phishing Page Is Only Part of the Attack

Wazza demonstrates that the phishing page is only the final stage of a more controlled delivery system. Behind the link, attackers can use campaign checks, session tokens, browser validation, and layered routing to control who reaches the lure.

For defenders, understanding that attack chain is just as important as identifying the final URL. For MSSPs, combining interactive sandboxing, threat intelligence, and integrations helps turn individual investigations into actionable intelligence that can protect multiple environments.

Effective phishing defense means understanding what happens behind the link and turning that visibility into scalable protection.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.