Wazza phishkit multi-stage routing delivery
Malware Activity
Summary
Hide ▲
Show ▼
The Wazza phishkit now hides its phishing page behind multi-stage routing, session tokens, and browser telemetry checks, making the lure harder to reproduce and detect. It screens automated traffic before showing an Adobe-themed Device Code page to targeted organizations across the US, Europe, and Australia. Defenders get a smaller initial signal and a more evasive delivery chain to investigate.
Related Happenings
Wazza phishkit campaign targeting banking, manufacturing, and government organizations
Campaign
H score33
First: 08.10.2026 13:30
Last: 08.10.2026 13:30
Sources 1
How related:
ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.
About this happening:
The Wazza phishing campaign is targeting banking, manufacturing, and government organizations across the US, Europe, and Australia, and it is using multi-stage routi...
Wazza phishkit campaign targeting banking, manufacturing, and government organizations
CampaignHow related: ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.
About this happening: The Wazza phishing campaign is targeting banking, manufacturing, and government organizations across the US, Europe, and Australia, and it is using multi-stage routi...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
PhantomEnigma trusted-delivery phishing campaign abusing Brazilian government websites
Campaign
H score25
First: 16.07.2026 14:58
Last: 16.07.2026 14:58
Sources 1
About this happening:
The PhantomEnigma campaign abused more than 20 Brazilian government websites and compromised email infrastructure to route malware through trusted .gov.br links, incre...
PhantomEnigma trusted-delivery phishing campaign abusing Brazilian government websites
CampaignAbout this happening: The PhantomEnigma campaign abused more than 20 Brazilian government websites and compromised email infrastructure to route malware through trusted .gov.br links, incre...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware Activity
H score33
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware ActivityAbout this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Google DoubleClick malspam campaign delivering DesckVB RAT
Campaign
H score33
First: 03.06.2026 19:29
Last: 03.06.2026 19:29
Sources 1
About this happening:
A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Google DoubleClick malspam campaign delivering DesckVB RAT
CampaignAbout this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Timeline
-
08.10.2026 13:30 2 articles · 11h ago
Wazza phishkit screens traffic before showing an Adobe-themed Device Code page
Initial DisclosureANY.RUN identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The kit uses a multi-stage routing chain, session tokens, and browser telemetry checks to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page, making the initial link less informative and complicating automated detection.
Show sources
- Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia — thehackernews.com — 08.10.2026 13:30
- Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia — thehackernews.com — 08.10.2026 13:30