Scworld Wazza Phishkit Employs Multi-Stage Routing to Target Key Sectors
Article Content
- •Wazza targets banking, government, and manufacturing sectors across multiple regions.
- •The phishing kit uses a multi-stage routing chain to evade detection.
- •MSSPs may experience increased investigation times due to the complexity of the attack.
A new phishing kit named Wazza has been identified, targeting banking, government, and manufacturing sectors across the US, Europe, and Australia. This sophisticated attack uses a multi-stage routing chain to filter visitors and automated traffic before delivering a final payload, which is an Adobe-themed Device Code phishing page. The attack begins at a wildcard landing domain and involves several endpoints that check for active campaigns and generate session tokens. Only after passing these checks does the visitor reach the phishing page, complicating detection efforts. Managed Security Service Providers (MSSPs) face challenges in investigating alerts due to the complexity of the attack chain. The campaign exemplifies a trend where attackers enhance their phishing infrastructure to evade detection.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What sectors are targeted by Wazza?
How does Wazza evade detection?
What challenges do MSSPs face with Wazza?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…