As detailed in The Hacker News, a sophisticated new phishing kit named Wazza has been identified, employing a multi-stage routing chain to screen visitors and automated traffic before delivering its final payload. This advanced technique moves beyond simple login page replication, integrating filtering and traffic controls directly into the infrastructure that hosts the phishing page.
Wazza targets banking, manufacturing, and government organizations across the U.S., Europe, and Australia. The attack chain begins at a wildcard landing domain, which passes visitors through several endpoints, including one that checks for active campaigns and another that generates a short-lived signed session token. This token is then validated, along with browser telemetry, at an anti-bot gate to filter unwanted traffic. Only after these checks are passed does the visitor reach the final Adobe-themed Device Code phishing page. This layered approach makes initial detection more challenging, as the malicious behavior is not immediately apparent from a single URL. For Managed Security Service Providers (MSSPs), this complexity increases investigation times and the potential for unnecessary escalations, as reproducing the full attack sequence can be difficult. The campaign highlights a growing trend where attackers build evasive infrastructure around their phishing lures, making them harder to identify and block.
Source: The Hacker News
