New Wazza Phishing Kit Screens Visitors Before Showing Its Fake Adobe Login
Phishing kits are evolving beyond copying a login page and waiting for credentials. ANY.RUN has identified a new kit called Wazza, which targets banking, manufacturing and government organisations across the US, Europe and Australia. Attackers are building filtering, session management and traffic controls into the infrastructure that delivers the phishing page.
Wazza does not send every visitor straight to its final page. A visitor lands on a wildcard domain and is checked against an active campaign. A separate service then issues a marker to correlate the visit, and a short-lived signed session token is generated. The token and browser telemetry are validated to filter out unwanted traffic, including automated scanners. Only visitors who pass these checks reach the final Adobe-themed Device Code phishing page.
This matters because the first link a user clicks reveals little about where it leads, which may complicate automated detection. The source notes this can also slow investigations and cause unnecessary escalations, especially for managed security providers handling alerts across many customers. The Adobe theme gives the page a familiar look, while the Device Code flow targets account authentication rather than relying only on conventional password theft.