Phishing attacks have evolved beyond simple deceptive login pages. Attackers now incorporate sophisticated features like filtering, session management, and traffic control into their phishing kits. A recent case is the Wazza phishkit, identified by ANY.RUN, which targets banking, manufacturing, and government sectors across the US, Europe, and Australia. This campaign employs a multi-stage routing mechanism to screen visitors before presenting an Adobe-themed Device Code phishing page.
Understanding the Wazza Phishkit Attack Chain
Wazza’s approach involves a complex routing process that does not immediately direct every visitor to its phishing page. Instead, it uses a series of checks to determine which requests reach the final payload. Initially, visitors land on a wildcard domain, which checks the hostname’s campaign status. This is followed by a sequence involving client markers and session tokens to filter out unwanted traffic. Only after these steps does the visitor reach the Adobe-themed phishing page, designed to appear routine and familiar.
The attack chain exemplifies a layered approach, making early detection challenging for security teams. The infrastructure first validates the visitor before executing the social engineering component, complicating automated detection and increasing investigation times for security analysts.
Impact on Managed Security Service Providers (MSSPs)
For MSSPs, the Wazza phishkit presents a unique challenge. Unlike a straightforward malicious URL, Wazza’s evasive techniques mean analysts must manage alerts across various customer environments. The routing chain can make URLs seem benign, leading to increased investigation times and unnecessary escalations. Automated systems may not replicate the same user experience, further complicating the analysis process.
ANY.RUN’s Interactive Sandbox offers a solution by allowing analysts to interact with suspicious URLs in a controlled environment. This tool enables a comprehensive examination of the attack chain, providing valuable intelligence that can reduce the need for escalation and improve response times.
The Broader Implications of Wazza’s Technique
Wazza’s targeting of high-value sectors like banking, government, and manufacturing highlights the attractiveness of their sensitive data to attackers. These organizations manage critical processes and information, making them prime targets. However, the technique’s adaptability means it could be used against various industries. The Adobe branding is a tactic to make phishing attempts appear legitimate, aiming to trick users into granting access to their accounts.
By integrating threat intelligence into existing security workflows, organizations can improve their defenses. ANY.RUN’s Threat Intelligence Feeds transform findings into ongoing monitoring, offering near-real-time protection and minimizing false positives. This scalable approach allows MSSPs to efficiently protect multiple environments without repetitive investigations.
Wazza’s campaign illustrates that the phishing page is just the final step in a controlled delivery system. Understanding the entire attack chain is crucial for effective defense. With tools like ANY.RUN, security teams can turn individual investigations into actionable intelligence, enhancing overall protection.
