Threat Intelligence, Phishing

Wazza phishkit uses multi-stage routing to evade detection

As detailed in The Hacker News, a sophisticated new phishing kit named Wazza has been identified, employing a multi-stage routing chain to screen visitors and automated traffic before delivering its final payload. This advanced technique moves beyond simple login page replication, integrating filtering and traffic controls directly into the infrastructure that hosts the phishing page.

Wazza targets banking, manufacturing, and government organizations across the U.S., Europe, and Australia. The attack chain begins at a wildcard landing domain, which passes visitors through several endpoints, including one that checks for active campaigns and another that generates a short-lived signed session token. This token is then validated, along with browser telemetry, at an anti-bot gate to filter unwanted traffic. Only after these checks are passed does the visitor reach the final Adobe-themed Device Code phishing page. This layered approach makes initial detection more challenging, as the malicious behavior is not immediately apparent from a single URL. For Managed Security Service Providers (MSSPs), this complexity increases investigation times and the potential for unnecessary escalations, as reproducing the full attack sequence can be difficult. The campaign highlights a growing trend where attackers build evasive infrastructure around their phishing lures, making them harder to identify and block.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds