Threat reportPhishingTL-2026-3039
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Wazza Phishkit Targets Banking, Government, and (TL-2026-3039), also tracked as Wazza, is a high-severity phishing campaign, first published 2026-10-08. It has no confirmed attribution, affects Multiple Organizations in banking, government and manufacturing, maps to 8 MITRE ATT&CK techniques (T1036, T1078.004, T1480), and is covered by 9 detection rules and 11 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 11Indicators of compromise
Key facts for TL-2026-3039
- Threat ID
- TL-2026-3039
- Also known as
- Wazza
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- banking, government administration, manufacturing
- Target regions
- North America, Europe, australia
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Wazza Phishkit Targets Banking, Government, and
Malware and tooling: Wazza
How Wazza Phishkit Targets Banking, Government, and works
ANY.RUN reported a previously unreported phishkit, Wazza, that targets banking, government and manufacturing organizations in the US, Europe and Australia. It routes visitors through a token-gated, multi-stage chain with browser telemetry validation and anti-bot filtering before serving an Adobe-themed OAuth Device Code phishing page.
Wazza is a phishing kit documented by ANY.RUN and published via a partner-contributed article on The Hacker News on 2026-10-08. Rather than serving a static credential-harvesting page, the kit controls who reaches the lure and under what conditions, using a multi-stage routing chain to screen visitors and automated traffic.
Per the source, the chain begins at a wildcard landing domain (*.boegl-krysl.eu). The landing host calls /api/wazza-config, which checks whether the requested hostname belongs to an active campaign (the article refers to 'allowed campaign prefixes'). Infrastructure on a Cloudflare workers.dev host (beacon-surge-sync[...].workers.dev, truncated in the source) issues a client marker used to correlate the visit. The /api/mint-token endpoint then creates a short-lived signed session token, which is presented to check.boegl-krysl.eu; that host validates the token and browser telemetry and filters unwanted traffic. Only approved visitors proceed through boegl-krysl.eu/r and /meline to the final stage, an Adobe-themed Device Code phishing page. A URL can therefore appear benign to automated scanners that fail the gate.
The Device Code lure targets account authentication rather than relying solely on conventional password harvesting. In the broader device code phishing pattern (BleepingComputer/Push Security, Arctic Wolf), the attacker obtains a device code from the identity provider, the victim is induced to enter it on the legitimate login page, and the attacker's device receives valid access and refresh tokens. The source does not state which identity provider Wazza abuses, the signing algorithm or lifetime of the session token, the lure delivery channel, any threat actor, or victim counts. The source lists potential impact as account compromise, trusted identity abuse, follow-on phishing from compromised business identities, infrastructure discovery via the routing chain, and increased incident response effort.
The source is vendor-promotional and uncorroborated by a second source; searches found no other public reporting on Wazza or the listed domains, and BeaconBeagle returned no match for boegl-krysl.eu. Severity HIGH is an analyst assignment.
MITRE ATT&CK techniques used in TL-2026-3039
Defense Evasion
T1036 Masquerading; T1480 Execution Guardrails
Initial Access
Credential Access
T1528 Steal Application Access Token
Lateral Movement
lateral-movement
T1550.001 Application Access Token
Resource Development
Affected products and versions in Wazza Phishkit Targets Banking, Government, and
- Multiple — Organizations in banking, government and manufacturing sectors (OAuth device code authentication flows)
Remediation for Wazza Phishkit Targets Banking, Government, and
Immediate actions
- Block and monitor boegl-krysl.eu and all subdomains (including check.boegl-krysl.eu) at DNS, proxy and email gateways
- Search proxy/DNS logs for requests to *.boegl-krysl.eu and the /api/wazza-config, /api/mint-token, /r and /meline paths
- Review identity-provider sign-in logs for unexpected device code authentication events and revoke refresh tokens and sessions for affected users
Workarounds
- Restrict device code authentication to named devices, networks or users
- Alert on device code sign-ins from unusual IP addresses or sessions
Longer-term hardening
- Disable the OAuth device code flow where it is not needed using Conditional Access policies
- Train users that a code-entry prompt reached from an unsolicited link or document-sharing page should be reported, not completed
- Detonate suspicious links in a sandbox that can pass multi-stage gating rather than relying on static URL reputation
Timeline of Wazza Phishkit Targets Banking, Government, and
- Push Security reports device code phishing pages detected in early March 2026 up 15x for the year, the broader trend context for Wazza (approximate date; source says 'early March').
- BleepingComputer reports the device code phishing surge at 37.5x, citing Push Security tracking of at least 11 kits with SaaS lures (including Adobe), anti-bot protections and cloud hosting.
- Analyst pivot: BeaconBeagle configs search for boegl-krysl.eu returned no matches; web searches found no corroborating public reporting of the domains.
- Final stage is an Adobe-themed Device Code phishing page aimed at account authentication rather than only password harvesting; targets are banking, government and manufacturing in the US, Europe and Australia.
- check.boegl-krysl.eu validates the token and browser telemetry and filters unwanted or automated traffic; only approved visitors continue via boegl-krysl.eu/r and /meline.
- Reported chain: wildcard landing on *.boegl-krysl.eu, /api/wazza-config campaign-prefix check, client marker from a workers.dev host, then /api/mint-token issues a short-lived signed session token.
- ANY.RUN's Wazza analysis is published via The Hacker News (partner-contributed piece); the sandbox task URL analyzed was on fmegqzgznk.boegl-krysl.eu. The first-seen date of the kit is not stated.
Sources cited for Wazza Phishkit Targets Banking, Government, and
- Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia (The Hacker News)
- ANY.RUN sandbox analysis of Wazza phishing URL
- Device code phishing attacks surge 37x as new kits spread online (BleepingComputer)
- The Device Code Phishing Tsunami: What We're Seeing in the Wild (LevelBlue SpiderLabs)
- Arctic Wolf: device code phishing and OAuth token theft
- Artoken: inside an EvilTokens affiliate panel targeting Microsoft 365 (Cisco Talos)
- It's raining phish and scams: how Cloudflare pages.dev and workers.dev domains get abused (LevelBlue SpiderLabs)
Detection coverage for TL-2026-3039
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3039 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.