# Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

> ANY.RUN reported a previously unreported phishkit, Wazza, that targets banking, government and manufacturing organizations in the US, Europe and Australia. It routes visitors through a token-gated, multi-stage chain with browser telemetry validation and anti-bot filtering before serving an Adobe-themed OAuth Device Code phishing page.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3039
- **ID:** TL-2026-3039
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Wazza is a phishing kit documented by ANY.RUN and published via a partner-contributed article on The Hacker News on 2026-10-08. Rather than serving a static credential-harvesting page, the kit controls who reaches the lure and under what conditions, using a multi-stage routing chain to screen visitors and automated traffic.

Per the source, the chain begins at a wildcard landing domain (*.boegl-krysl.eu). The landing host calls /api/wazza-config, which checks whether the requested hostname belongs to an active campaign (the article refers to 'allowed campaign prefixes'). Infrastructure on a Cloudflare workers.dev host (beacon-surge-sync[...].workers.dev, truncated in the source) issues a client marker used to correlate the visit. The /api/mint-token endpoint then creates a short-lived signed session token, which is presented to check.boegl-krysl.eu; that host validates the token and browser telemetry and filters unwanted traffic. Only approved visitors proceed through boegl-krysl.eu/r and /meline to the final stage, an Adobe-themed Device Code phishing page. A URL can therefore appear benign to automated scanners that fail the gate.

The Device Code lure targets account authentication rather than relying solely on conventional password harvesting. In the broader device code phishing pattern (BleepingComputer/Push Security, Arctic Wolf), the attacker obtains a device code from the identity provider, the victim is induced to enter it on the legitimate login page, and the attacker's device receives valid access and refresh tokens. The source does not state which identity provider Wazza abuses, the signing algorithm or lifetime of the session token, the lure delivery channel, any threat actor, or victim counts. The source lists potential impact as account compromise, trusted identity abuse, follow-on phishing from compromised business identities, infrastructure discovery via the routing chain, and increased incident response effort.

The source is vendor-promotional and uncorroborated by a second source; searches found no other public reporting on Wazza or the listed domains, and BeaconBeagle returned no match for boegl-krysl.eu. Severity HIGH is an analyst assignment.

## MITRE ATT&CK

- T1583.001 Domains
- T1583.006 Web Services
- T1480 Execution Guardrails
- T1036 Masquerading
- T1528 Steal Application Access Token
- T1550.001 Application Access Token
- T1078.004 Cloud Accounts
- T1534 Internal Spearphishing

## Sources

- [Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia (The Hacker News)](https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html)
- [ANY.RUN sandbox analysis of Wazza phishing URL](https://app.any.run/tasks/be1f83a0-742a-42de-afe4-c20110ef667f/)
- [Device code phishing attacks surge 37x as new kits spread online (BleepingComputer)](https://www.bleepingcomputer.com/news/security/device-code-phishing-attacks-surge-37x-as-new-kits-spread-online/)
- [The Device Code Phishing Tsunami: What We're Seeing in the Wild (LevelBlue SpiderLabs)](https://www.levelblue.com/blogs/spiderlabs-blog/the-device-code-phishing-tsunami-what-were-seeing-in-the-wild)
- [Arctic Wolf: device code phishing and OAuth token theft](https://arcticwolf.com/?p=131168)
- [Artoken: inside an EvilTokens affiliate panel targeting Microsoft 365 (Cisco Talos)](https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/)
- [It's raining phish and scams: how Cloudflare pages.dev and workers.dev domains get abused (LevelBlue SpiderLabs)](https://www.levelblue.com/blogs/spiderlabs-blog/its-raining-phish-and-scams-how-cloudflare-pages-dev-and-workers-dev-domains-get-abused)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3039
