Skip to content
Wazza Phishkit Employs Multi-Stage Routing to Target Key Sectors

Wazza Phishkit Employs Multi-Stage Routing to Target Key Sectors

First seen 9 Oct 2026, 17:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 21:38 UTC
  • •Wazza targets banking, government, and manufacturing sectors across multiple regions.
  • •The phishing kit uses a multi-stage routing chain to evade detection.
  • •MSSPs may experience increased investigation times due to the complexity of the attack.

A new phishing kit named Wazza has been identified, targeting banking, government, and manufacturing sectors across the US, Europe, and Australia. This sophisticated attack uses a multi-stage routing chain to filter visitors and automated traffic before delivering a final payload, which is an Adobe-themed Device Code phishing page. The attack begins at a wildcard landing domain and involves several endpoints that check for active campaigns and generate session tokens. Only after passing these checks does the visitor reach the phishing page, complicating detection efforts. Managed Security Service Providers (MSSPs) face challenges in investigating alerts due to the complexity of the attack chain. The campaign exemplifies a trend where attackers enhance their phishing infrastructure to evade detection.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-08
Wazza phishkit identified
ANY.RUN reported the discovery of the Wazza phishkit targeting key sectors with advanced techniques.
The Hacker News
2026-10-09
Wazza phishkit details published
Scworld published a brief detailing Wazza's multi-stage routing and its implications for detection.
Scworld

More articles in this cluster (2)

Common questions

What sectors are targeted by Wazza?
Wazza targets banking, government, and manufacturing sectors across the US, EU, and Australia.
How does Wazza evade detection?
Wazza employs a multi-stage routing chain to filter traffic and validate visitors before delivering the phishing page.
What challenges do MSSPs face with Wazza?
MSSPs may encounter longer investigation times due to the complexity of the attack chain and the need to reproduce the full attack sequence.