Full Report
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe
Analysis Summary
# Tool/Technique: Wazza Phishkit
## Overview
Wazza is a sophisticated, new-generation phishing kit (phishkit) designed to target high-value sectors including banking, manufacturing, and government organizations. Unlike traditional phishing kits that only replicate login pages, Wazza utilizes a complex multi-stage routing infrastructure to perform visitor screening, bot detection, and session management before delivering its final malicious payload.
## Technical Details
- **Type:** Phishkit / Phishing Framework
- **Platform:** Web-based (Cross-platform; targets browsers across US, EU, and Australia)
- **Capabilities:** Multi-stage routing, anti-bot filtering, session tokenization, and Device Code phishing lures.
- **First Seen:** October 2026 (Reported date)
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- **[T1566.002 - Phishing: Spearphishing Link]**
- **[TA0007 - Discovery]**
- **[T1082 - System Information Discovery]** (via browser telemetry for filtering)
- **[TA0006 - Credential Access]**
- **[T1528 - Steal Application Access Token]** (Device Code flow exploitation)
- **[TA0005 - Defense Evasion]**
- **[T1564 - Hide Artifacts]** (Use of multi-stage routing to obscure the final lure)
## Functionality
### Core Capabilities
- **Multi-Stage Routing:** Uses a chain of redirects and API calls to hide the final phishing page from automated scanners and security researchers.
- **Campaign Validation:** Employs an `/api/wazza-config` endpoint to verify if the accessed hostname corresponds to an active, authorized campaign.
- **Session Minting:** Generates short-lived, signed session tokens via `/api/mint-token` to manage victim interactions and prevent replay attacks or unauthorized access to the kit.
### Advanced Features
- **Anti-Bot and Telemetry Filtering:** Validates browser telemetry and client markers (via Cloudflare Workers) to filter out security sandboxes and automated crawlers.
- **Device Code Phishing:** Instead of standard password harvesting, it utilizes an Adobe-themed "Device Code" flow, allowing attackers to hijack authenticated sessions and bypass certain Multi-Factor Authentication (MFA) implementations.
- **Wildcard Landing Domains:** Uses wildcard subdomains (e.g., `[.]boegl-krysl[.]eu`) to make the initial entry point appear less suspicious and more dynamic.
## Indicators of Compromise
- **File Hashes:** *(Not specified in the article as it is a web-based infrastructure threat)*
- **File Names:** `wazza-config` (API endpoint), `/meline` (Final stage path)
- **Network Indicators:**
- `boegl-krysl[.]eu` (Root domain)
- `check[.]boegl-krysl[.]eu` (Validation gate)
- `beacon-surge-sync[.]workers[.]dev` (Client marker/sync)
- `[.]boegl-krysl[.]eu/r` (Redirector path)
- `[.]boegl-krysl[.]eu/api/wazza-config` (Configuration API)
- **Behavioral Indicators:**
- Sequential requests from wildcard subdomains to specific API endpoints (`mint-token`).
- Short-lived signed tokens passed in URL parameters or headers.
## Associated Threat Actors
- Currently unattributed (Identified by ANY.RUN as a new threat targeting US, EU, and Australia).
## Detection Methods
- **Signature-based detection:** Monitoring for the specific URI patterns associated with the Wazza API (e.g., `/api/wazza-config`, `/api/mint-token`).
- **Behavioral detection:** Identifying high-frequency redirects between newly registered or suspicious wildcard domains and known worker services like `workers.dev`.
- **Infrastructure Monitoring:** Flagging the use of Device Code flow prompts originating from non-standard or recently registered domains.
## Mitigation Strategies
- **Prevention measures:** Implementation of FIDO2-based hardware security keys to mitigate Device Code and session hijacking.
- **Hardening recommendations:** Block access to known suspicious wildcard domains and restrict the use of Device Code authentication flows if not required for business operations.
- **User Training:** Educating employees on the appearance of Device Code phishing lures, specifically those mimicking Adobe or Microsoft 365 services.
## Related Tools/Techniques
- **Adversary-in-the-Middle (AiTM):** Similar intent to bypass MFA.
- **Evilginx/Mophish:** Frameworks that also use proxying and session management for advanced phishing.