Find notable cyber news and cases, enriched with sources, timelines, and signals.

Wazza phishkit campaign targeting banking, manufacturing, and government organizations

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The Wazza phishing campaign is targeting banking, manufacturing, and government organizations across the US, Europe, and Australia, and it is using multi-stage routing to hide the final lure. The kit screens visitors and automated traffic before serving an Adobe-themed Device Code phishing page. That evasive delivery pattern raises the chance that initial links will look benign until they are detonated in the right environment.

Related Happenings

Wazza phishkit multi-stage routing delivery

Malware Activity
H score22 First: 08.10.2026 13:30 Last: 08.10.2026 13:30 Sources 1

How related: Wazza does not send every visitor directly to its phishing page. Instead, the phishkit uses a multi-stage routing chain to determine which requests should reach the final payload.

About this happening: The Wazza phishkit now hides its phishing page behind multi-stage routing, session tokens, and browser telemetry checks, making the lure harder to reproduce an...

CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools

Campaign
H score30 First: 30.09.2026 13:45 Last: 30.09.2026 13:45 Sources 1

About this happening: The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign
H score38 First: 24.07.2026 18:12 Last: 24.07.2026 18:12 Sources 1

About this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...

Google DoubleClick malspam campaign delivering DesckVB RAT

Campaign
H score33 First: 03.06.2026 19:29 Last: 03.06.2026 19:29 Sources 1

About this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...

OAuth device-code phishing campaign targeting SaaS accounts

Campaign
H score43 First: 04.04.2026 17:17 Last: 04.04.2026 17:17 Sources 1

About this happening: A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...

Timeline

  1. 08.10.2026 13:30 2 articles · 11h ago

    Wazza phishkit targets banking, manufacturing, and government organizations

    Initial Disclosure

    Wazza is a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain with session tokens and browser telemetry to screen visitors before delivering an Adobe-themed Device Code phishing page, making the initial URL less informative and complicating automated detection.

    Show sources