
Phishing kits are now not restricted to copying a well-known login web page and ready for a sufferer to enter credentials. Attackers are more and more constructing filtering, session administration, and visitors controls into the infrastructure that delivers the phishing web page itself.
ANY.RUN has recognized Wazza, a brand new phishkit focusing on banking, manufacturing, and authorities organizations throughout the US, Europe, and Australia. The marketing campaign makes use of a multi-stage routing chain to display screen guests and automatic visitors earlier than delivering an Adobe-themed Machine Code phishing web page.
For safety groups, that makes Wazza greater than one other malicious URL. The marketing campaign exhibits how attackers can management the trail to the ultimate lure, making the preliminary hyperlink much less informative and probably complicating automated detection.
MSSPs face an added problem, as they examine alerts throughout a number of buyer environments whereas protecting response instances underneath management. That uncertainty can translate straight into longer investigation instances and pointless escalations.
Wazza Makes use of Multi-Stage Routing to Conceal Its Phishing Web page
Wazza doesn’t ship each customer on to its phishing web page. As a substitute, the phishkit makes use of a multi-stage routing chain to find out which requests ought to attain the ultimate payload.
To see how this works in observe, let’s comply with a Wazza evaluation in ANY.RUN’s Interactive Sandbox.
![]() |
| Wazza attack chain exposed in ANY.RUN’s Interactive Sandbox |
The flow begins at a wildcard landing domain, [.]boegl-krysl[.]eu, where the visitor is passed to /api/wazza-config. This endpoint checks whether the hostname belongs to an active campaign.
![]() |
| Wildcard routing config and allowed campaign prefixes in the Wazza attack analysis |
The infrastructure then contacts beacon-surge-sync[…]workers[.]dev, which issues a client marker that can be used to correlate the visit. Next, /api/mint-token generates a short-lived signed session token.
![]() |
| Short-lived signed token for the current session after detonating a Wazza sample |
That token is passed to check[.]boegl-krysl[.]eu, where Wazza validates the token and browser telemetry and filters unwanted traffic.
![]() |
| A Wazza attack: Minted token passed into the anti-bot validation gate |
Only after these checks does the visitor continue through boegl-krysl[.]eu/r and /meline, eventually reaching the final Adobe-themed Device Code phishing page.
![]() |
| Final stage of a Wazza attack: Adobe-themed Device Code phishing landing |
Using a recognizable service as the visual theme gives the final stage a familiar appearance, while the Device Code flow provides the attacker with a way to target account authentication rather than relying solely on conventional password harvesting.
That makes the final lure only one component of a larger operation. The infrastructure first determines whether the visitor should be shown the phishing page. The social-engineering component comes afterward, once the campaign has established a session it considers suitable.
This layered approach is important for defenders because a URL can appear relatively unremarkable until its behavior is reproduced in the right environment.
Give your team the context to investigate phishing threats faster and ensure 30% less Tier 1 to Tier 2 escalations.
Integrate ANY.RUN
Wazza’s Reach Across Key Sectors: Government, Banking, and Manufacturing
ANY.RUN identified Wazza activity across the US, Europe, and Australia, with banking, manufacturing, and government among the targeted sectors.
![]() |
| Regions and sectors targeted by Wazza |
These organizations operate high-value business processes and manage information that can be attractive to attackers. Financial institutions handle sensitive accounts and transactions, manufacturers depend on interconnected corporate environments and business systems, while government organizations manage sensitive information and critical services.
But the campaign’s relevance goes beyond those individual sectors. The Wazza infrastructure demonstrates a phishing delivery technique that can be adapted to different targets. The final branding can change, while the underlying approach — filtering visitors, validating sessions, and selectively delivering the lure — remains useful to attackers.
The Adobe theme also reflects how phishing operators continue to use familiar brands to make authentication requests appear routine.
The branding may change, but the objective is consistent: persuade the victim to complete an authentication action that can provide an attacker with access to an account or session.
Why Wazza Creates a Bigger Problem for MSSPs
For an MSSP, an evasive phishing kit creates a different challenge from a straightforward malicious URL.
The provider is not investigating a single environment. Analysts may be responsible for multiple customers, different security stacks, and large volumes of alerts, often while working against defined response and escalation requirements.
Wazza adds uncertainty to that workflow. A suspicious URL may initially appear benign because the final phishing page is not immediately served. Automated security systems may receive different content from a human visitor. And an analyst who cannot reproduce the complete routing sequence may have to escalate the investigation simply to determine what the URL actually delivers.
The result can be a familiar MSSP problem: more time spent investigating, more cases moving to senior analysts, and less capacity for genuinely complex incidents.
This is why the ability to interact with suspicious content in an isolated environment matters.
ANY.RUN’s Interactive Sandbox allows analysts to open suspicious URLs using virtual machines that start in under 10 seconds, interact with the resulting pages, follow redirects, and observe network and behavioral activity.
![]() |
| Wazza analyzed in ANY.RUN’s Interactive Sandbox |
Using the solutions, analysts can get comprehensive Tier 1 reports in around 40 seconds, IOCs, screenshots, process graphs, and MITRE ATT&CK mapping.
For an attack such as Wazza, the operational value is straightforward: The faster analysts can reproduce the attack chain and establish a reliable verdict, the less likely a phishing investigation is to consume disproportionate senior-analyst resources.
One Wazza Investigation Can Reveal More Than One IOC
The infrastructure behind Wazza should not be viewed simply as a list of domains to block.
Its multi-stage routing creates several intelligence pivots. An analyst can start with one suspicious URL and uncover additional domains, endpoints, redirect paths, and behavioral indicators linked to the campaign.
ANY.RUN Threat Intelligence Lookup (TI Lookup) provides another way to investigate these connections. Analysts can pivot from IOCs to related threat activity and use query updates to track changes over time.
![]() |
| Searching for Wazza in ANY.RUN’s TI Lookup |
For an MSSP, a suspicious Wazza domain found while investigating one customer can also become a starting point for hunting related activity across other environments. This helps analysts identify connections even when attackers change individual indicators but retain elements of the same campaign.
Continuous Threat Intelligence Turns Findings into Ongoing Monitoring
Blocking one Wazza domain does not necessarily end the campaign. Phishing infrastructure can change, domains can be replaced, and routing logic can be modified as attackers adapt to detection. A static IOC list therefore has a limited lifespan.
ANY.RUN Threat Intelligence Feeds (TI Feeds) are designed to turn IOCs into continuous monitoring by streaming 99% unique, validated indicators and behavior-based threat data into security environments. The solutioon also supports STIX/TAXII, API, and SDK, allowing intelligence to be incorporated into existing security workflows.
![]() |
| ANY.RUN’s real-time threat intelligence feeds with near-zero false positives |
Scale is the key advantage for an MSSP. An analyst can investigate a Wazza URL, identify useful indicators, validate them, and make that intelligence available to the systems monitoring customer environments. The provider does not need to manually repeat the same research for every customer that may be exposed.
The investigation effectively becomes a source of reusable detection intelligence.
Up to 58% more threats identified. Expand your threat coverage with fresh, high-confidence intelligence.
Explore TI Feeds
Using Integrations to Bring Intelligence into Security Workflows
Threat intelligence is most useful when it reaches the systems that analysts already use for detection and response.
ANY.RUN provides integrations with platforms including Microsoft Sentinel, Microsoft Defender, Splunk, Cortex XSOAR, IBM QRadar, MISP, TheHive, ThreatConnect, Tines, Torq, and others.
![]() |
| Use integrations to connect ANY.RUN to your security stack for unified protection |
For MSSPs, this is an important part of the workflow because security providers already have established processes for collecting alerts, enriching investigations, and triggering response actions.
The objective is not to create another isolated source of intelligence that analysts must check manually. That allows the outcome of one investigation to contribute to protection across the wider SOC.
The Potential Impact of a Wazza Phishing Attack
Wazza’s immediate objective is to deliver an Adobe-themed Device Code phishing page, but the potential impact does not necessarily end with the first successful authentication.
Potential outcomes include:
- Account compromise: A successful Device Code phishing flow can give attackers access to targeted accounts or sessions.
- Trusted identity abuse: A compromised account can provide a trusted identity for communicating with colleagues, partners, or customers.
- Follow-on phishing: Attackers can potentially use compromised business identities to launch additional phishing attempts.
- Infrastructure discovery: The routing chain provides additional domains, endpoints, and behavioral indicators that can help defenders understand the wider campaign.
- Increased response effort: When the malicious behavior is hidden behind multiple checks, reproducing the attack and establishing its scope can require additional analyst time.
The key distinction is that Wazza is not simply a phishing landing page. Its infrastructure is designed to control who reaches the lure and under what conditions, adding an evasive layer before the social-engineering component of the attack.
Turning Wazza Investigations into Scalable Protection
The strongest response to Wazza is not simply to block the domains associated with one campaign. The investigation can become the starting point for a repeatable process that turns individual findings into broader protection.
A suspicious URL can be detonated in an interactive sandbox to expose its behavior, giving Tier 1 analysts the context needed to make a decision without automatically escalating the case. Relevant IOCs can then be investigated through Threat Intelligence Lookup to identify associated activity.
Threat Intelligence Feeds can take those findings further by turning validated indicators into continuously updated intelligence. Instead of relying on a single block, MSSPs can use fresh threat data to help protect multiple customer environments as the campaign evolves.
The result is a workflow that moves from investigation to intelligence to protection, rather than ending when a single malicious URL is blocked.
That distinction matters for MSSPs because the scale of the problem is not defined by how many phishing URLs an analyst can investigate individually. It is defined by how much useful intelligence the team can extract from each investigation and how efficiently that intelligence can be applied across the customer base.
Cut 21 minutes from MTTR and help your MSSP team respond to client threats faster.
Accelerate Your MSSP Response
Wazza Shows Why the Phishing Page Is Only Part of the Attack
Wazza demonstrates that the phishing page is only the final stage of a more controlled delivery system. Behind the link, attackers can use campaign checks, session tokens, browser validation, and layered routing to control who reaches the lure.
For defenders, understanding that attack chain is just as important as identifying the final URL. For MSSPs, combining interactive sandboxing, threat intelligence, and integrations helps turn individual investigations into actionable intelligence that can protect multiple environments.
Effective phishing defense means understanding what happens behind the link and turning that visibility into scalable protection.











