Wazza phishkit campaign targeting banking, manufacturing, and government organizations
Campaign
Summary
Hide ▲
Show ▼
The Wazza phishing campaign is targeting banking, manufacturing, and government organizations across the US, Europe, and Australia, and it is using multi-stage routing to hide the final lure. The kit screens visitors and automated traffic before serving an Adobe-themed Device Code phishing page. That evasive delivery pattern raises the chance that initial links will look benign until they are detonated in the right environment.
Related Happenings
Wazza phishkit multi-stage routing delivery
Malware Activity
H score22
First: 08.10.2026 13:30
Last: 08.10.2026 13:30
Sources 1
How related:
Wazza does not send every visitor directly to its phishing page. Instead, the phishkit uses a multi-stage routing chain to determine which requests should reach the final payload.
About this happening:
The Wazza phishkit now hides its phishing page behind multi-stage routing, session tokens, and browser telemetry checks, making the lure harder to reproduce an...
Wazza phishkit multi-stage routing delivery
Malware ActivityHow related: Wazza does not send every visitor directly to its phishing page. Instead, the phishkit uses a multi-stage routing chain to determine which requests should reach the final payload.
About this happening: The Wazza phishkit now hides its phishing page behind multi-stage routing, session tokens, and browser telemetry checks, making the lure harder to reproduce an...
CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools
Campaign
H score30
First: 30.09.2026 13:45
Last: 30.09.2026 13:45
Sources 1
About this happening:
The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...
CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools
CampaignAbout this happening: The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
Google DoubleClick malspam campaign delivering DesckVB RAT
Campaign
H score33
First: 03.06.2026 19:29
Last: 03.06.2026 19:29
Sources 1
About this happening:
A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Google DoubleClick malspam campaign delivering DesckVB RAT
CampaignAbout this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
OAuth device-code phishing campaign targeting SaaS accounts
Campaign
H score43
First: 04.04.2026 17:17
Last: 04.04.2026 17:17
Sources 1
About this happening:
A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...
OAuth device-code phishing campaign targeting SaaS accounts
CampaignAbout this happening: A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...
Timeline
-
08.10.2026 13:30 2 articles · 11h ago
Wazza phishkit targets banking, manufacturing, and government organizations
Initial DisclosureWazza is a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain with session tokens and browser telemetry to screen visitors before delivering an Adobe-themed Device Code phishing page, making the initial URL less informative and complicating automated detection.
Show sources
- Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia — thehackernews.com — 08.10.2026 13:30
- Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia — thehackernews.com — 08.10.2026 13:30