Wazza phishing platform screens traffic before serving an Adobe lure
The Wazza phishkit screens visitors and filters bots before serving an Adobe-themed Device Code page, hitting banks, government and industry.
Original: The Hacker News
ANY.RUN researchers have described Wazza, a new phishkit aimed at banks, manufacturers and government organizations across the US, Europe and Australia. What sets it apart is not the fake login page but the infrastructure that decides who gets to see it at all.
The chain starts at a wildcard landing domain, [.]boegl-krysl[.]eu, which forwards the visitor to /api/wazza-config to check whether the hostname belongs to an active campaign. The infrastructure then calls beacon-surge-sync[…]workers[.]dev, which issues a client marker used to correlate the visit, and /api/mint-token, which mints a short-lived signed session token.
That token goes to check[.]boegl-krysl[.]eu, where Wazza validates it along with browser telemetry and screens out unwanted traffic. Only then does the visitor pass through boegl-krysl[.]eu/r and /meline to reach the final lure: an Adobe-themed Device Code phishing page.
Going after the Device Code flow means targeting account authentication itself rather than relying on password harvesting alone, and the familiar Adobe branding makes the authentication request look routine.
Why evasive phishing is harder to triage
A URL can look unremarkable until its behavior is reproduced in the right environment: the final page is not served immediately, and automated scanners may receive different content than a human visitor. An analyst who cannot reproduce the full routing sequence may end up escalating just to find out what the link delivers — extra investigation time and more cases pushed to senior staff, a familiar strain for MSSPs juggling alerts across many customers. The same infrastructure also offers several pivots: one suspicious URL can lead to additional domains, endpoints, redirect paths and behavioral indicators tied to the campaign.