Threat reportPhishingTL-2026-3039

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

highACTIVE

Wazza Phishkit Targets Banking, Government, and (TL-2026-3039), also tracked as Wazza, is a high-severity phishing campaign, first published 2026-10-08. It has no confirmed attribution, affects Multiple Organizations in banking, government and manufacturing, maps to 8 MITRE ATT&CK techniques (T1036, T1078.004, T1480), and is covered by 9 detection rules and 11 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
11Indicators of compromise

Key facts for TL-2026-3039

Threat ID
TL-2026-3039
Also known as
Wazza
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
banking, government administration, manufacturing
Target regions
North America, Europe, australia
Detection rules
9
Indicators of compromise
11

Malware and tooling in Wazza Phishkit Targets Banking, Government, and

Malware and tooling: Wazza

How Wazza Phishkit Targets Banking, Government, and works

ANY.RUN reported a previously unreported phishkit, Wazza, that targets banking, government and manufacturing organizations in the US, Europe and Australia. It routes visitors through a token-gated, multi-stage chain with browser telemetry validation and anti-bot filtering before serving an Adobe-themed OAuth Device Code phishing page.

Wazza is a phishing kit documented by ANY.RUN and published via a partner-contributed article on The Hacker News on 2026-10-08. Rather than serving a static credential-harvesting page, the kit controls who reaches the lure and under what conditions, using a multi-stage routing chain to screen visitors and automated traffic.

Per the source, the chain begins at a wildcard landing domain (*.boegl-krysl.eu). The landing host calls /api/wazza-config, which checks whether the requested hostname belongs to an active campaign (the article refers to 'allowed campaign prefixes'). Infrastructure on a Cloudflare workers.dev host (beacon-surge-sync[...].workers.dev, truncated in the source) issues a client marker used to correlate the visit. The /api/mint-token endpoint then creates a short-lived signed session token, which is presented to check.boegl-krysl.eu; that host validates the token and browser telemetry and filters unwanted traffic. Only approved visitors proceed through boegl-krysl.eu/r and /meline to the final stage, an Adobe-themed Device Code phishing page. A URL can therefore appear benign to automated scanners that fail the gate.

The Device Code lure targets account authentication rather than relying solely on conventional password harvesting. In the broader device code phishing pattern (BleepingComputer/Push Security, Arctic Wolf), the attacker obtains a device code from the identity provider, the victim is induced to enter it on the legitimate login page, and the attacker's device receives valid access and refresh tokens. The source does not state which identity provider Wazza abuses, the signing algorithm or lifetime of the session token, the lure delivery channel, any threat actor, or victim counts. The source lists potential impact as account compromise, trusted identity abuse, follow-on phishing from compromised business identities, infrastructure discovery via the routing chain, and increased incident response effort.

The source is vendor-promotional and uncorroborated by a second source; searches found no other public reporting on Wazza or the listed domains, and BeaconBeagle returned no match for boegl-krysl.eu. Severity HIGH is an analyst assignment.

MITRE ATT&CK techniques used in TL-2026-3039

Defense Evasion

T1036 Masquerading; T1480 Execution Guardrails

Initial Access

T1078.004 Cloud Accounts

Credential Access

T1528 Steal Application Access Token

Lateral Movement

T1534 Internal Spearphishing

lateral-movement

T1550.001 Application Access Token

Resource Development

T1583.001 Domains; T1583.006 Web Services

Affected products and versions in Wazza Phishkit Targets Banking, Government, and

  • Multiple — Organizations in banking, government and manufacturing sectors (OAuth device code authentication flows)

Remediation for Wazza Phishkit Targets Banking, Government, and

Immediate actions

  • Block and monitor boegl-krysl.eu and all subdomains (including check.boegl-krysl.eu) at DNS, proxy and email gateways
  • Search proxy/DNS logs for requests to *.boegl-krysl.eu and the /api/wazza-config, /api/mint-token, /r and /meline paths
  • Review identity-provider sign-in logs for unexpected device code authentication events and revoke refresh tokens and sessions for affected users

Workarounds

  • Restrict device code authentication to named devices, networks or users
  • Alert on device code sign-ins from unusual IP addresses or sessions

Longer-term hardening

  • Disable the OAuth device code flow where it is not needed using Conditional Access policies
  • Train users that a code-entry prompt reached from an unsolicited link or document-sharing page should be reported, not completed
  • Detonate suspicious links in a sandbox that can pass multi-stage gating rather than relying on static URL reputation

Timeline of Wazza Phishkit Targets Banking, Government, and

  • Push Security reports device code phishing pages detected in early March 2026 up 15x for the year, the broader trend context for Wazza (approximate date; source says 'early March').
  • BleepingComputer reports the device code phishing surge at 37.5x, citing Push Security tracking of at least 11 kits with SaaS lures (including Adobe), anti-bot protections and cloud hosting.
  • Analyst pivot: BeaconBeagle configs search for boegl-krysl.eu returned no matches; web searches found no corroborating public reporting of the domains.
  • Final stage is an Adobe-themed Device Code phishing page aimed at account authentication rather than only password harvesting; targets are banking, government and manufacturing in the US, Europe and Australia.
  • check.boegl-krysl.eu validates the token and browser telemetry and filters unwanted or automated traffic; only approved visitors continue via boegl-krysl.eu/r and /meline.
  • Reported chain: wildcard landing on *.boegl-krysl.eu, /api/wazza-config campaign-prefix check, client marker from a workers.dev host, then /api/mint-token issues a short-lived signed session token.
  • ANY.RUN's Wazza analysis is published via The Hacker News (partner-contributed piece); the sandbox task URL analyzed was on fmegqzgznk.boegl-krysl.eu. The first-seen date of the kit is not stated.

Sources cited for Wazza Phishkit Targets Banking, Government, and

Detection coverage for TL-2026-3039

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3039 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
11 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats