Security researchers at ANY.RUN have identified a new phishing kit, Wazza, that adds filtering and session management to the phishing delivery process. Instead of sending every visitor straight to a fake login page, the kit uses a multi-stage routing chain to decide who should see the final lure.
The chain starts at a wildcard landing domain, where an endpoint checks if the hostname belongs to an active campaign. The infrastructure then contacts a separate domain to issue a client marker, and later mints a short-lived signed session token. That token is validated at another checkpoint along with browser telemetry, filtering out unwanted traffic. Only after passing those checks does the visitor reach the final page: an Adobe-themed Device Code phishing page.
ANY.RUN observed Wazza activity across the US, Europe, and Australia, hitting banking, manufacturing, and government organizations. The Device Code flow targets account authentication rather than just password entry, and the multi-stage approach means a URL can look unremarkable until the full chain is reproduced in the right environment. For MSSPs, that uncertainty can lead to longer investigations and more escalations, since the final payload is not served to every visitor.