Security1 publisherNot yet confirmed elsewhere2 min readPublished
Wazza phishkit screens visitors through a multi-stage chain before serving its Adobe device-code lure
ANY.RUN says the Wazza phishkit routes visitors through a multi-stage filtering chain before serving an Adobe-themed device-code phishing page. The chain screens out automated traffic, so the first link gives banking, government and manufacturing defenders little to analyze.
The Watch · Security desk
What happened
- A Cloudflare workers.dev host issues a correlation marker, and /api/mint-token then mints a short-lived signed session token for the visit.
- check[.]boegl-krysl[.]eu validates that token against browser telemetry and drops unwanted traffic before routing the survivor on to the Adobe page.
- The final page runs an OAuth device-code flow that goes after account authentication, not only a harvested password.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint A one-shot fetch of the first link renders nothing malicious, because the page only loads once the chain accepts the token and telemetry, so point-in-time URL scanning under-reports the campaign.
- precedent The Adobe skin is swappable, so taking down the lure page does not retire the filter-validate-then-deliver delivery, which can be re-branded against other sectors.
- exposure Because the device-code flow targets the authenticated session rather than the password, rotating a stolen credential does not necessarily close the compromised account.
- cost An evasive kit across many customer environments means longer investigations and more escalations for the MSSP analyst who has to clear each alert.
A visitor landing on boegl-krysl[.]eu is passed to /api/wazza-config, which checks whether the hostname belongs to a live campaign [3]. The infrastructure then calls beacon-surge-sync[...]workers[.]dev for a client marker, mints a short-lived signed token at /api/mint-token, and sends that token to check[.]boegl-krysl[.]eu, which validates it against browser telemetry and drops traffic it does not want [4][5][6]. Only visitors that clear those gates continue through boegl-krysl[.]eu/r and /meline to the Adobe page [7]. By ANY.RUN's account the visitor crosses at least three distinct hostnames before any phishing content loads [13].
ANY.RUN says a URL can look unremarkable until its behavior is reproduced in the right environment, and that the infrastructure decides whether to show the page before any social engineering starts [9][10]. A scanner that fetches the first link once, without a valid token or the expected telemetry, sees a hop that does nothing.
The final stage uses an Adobe theme and an OAuth device-code flow, which ANY.RUN says lets the operator target account authentication instead of only harvesting a password [8]. The branding is the replaceable part. ANY.RUN says the approach of filtering visitors, validating sessions, and selectively delivering the lure stays useful behind a different logo [11].
The writeup does not name a threat actor, cite a CVE, or give victim counts or dates. The attribution rests on ANY.RUN alone [1]. It does name the sectors, banking, manufacturing and government, and the geographies, the US, Europe and Australia [1].
The analysis is ANY.RUN's own, and it ends on a sales line: the company says its sandbox context delivers 30% fewer Tier 1 to Tier 2 escalations [14]. That number describes the product, not the campaign.
What to watch
- Whether other researchers corroborate ANY.RUN's attribution and publish indicators for the boegl-krysl[.]eu and check[.]boegl-krysl[.]eu infrastructure.
- Whether the same filtering chain reappears under non-Adobe branding against new targets.
- Whether Cloudflare removes the beacon-surge-sync workers.dev correlation endpoint and /api/mint-token token service.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives80
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
ANY.RUN identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.
- [2]
The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.
- [3]
The flow begins at wildcard landing domain boegl-krysl[.]eu, where the visitor is passed to /api/wazza-config, which checks whether the hostname belongs to an active campaign.
- [4]
The infrastructure contacts beacon-surge-sync[...]workers[.]dev, which issues a client marker that can be used to correlate the visit.
- [5]
The /api/mint-token endpoint generates a short-lived signed session token.
- [6]
The token is passed to check[.]boegl-krysl[.]eu, where Wazza validates the token and browser telemetry and filters unwanted traffic.
- [7]
Only after these checks does the visitor continue through boegl-krysl[.]eu/r and /meline, reaching the final Adobe-themed Device Code phishing page.
- [8]
ANY.RUN says the Device Code flow provides the attacker with a way to target account authentication rather than relying solely on conventional password harvesting.
- [9]
ANY.RUN says a URL can appear relatively unremarkable until its behavior is reproduced in the right environment.
- [10]
ANY.RUN says the infrastructure first determines whether the visitor should be shown the phishing page, with the social-engineering component coming only after a suitable session is established.
- [11]
ANY.RUN says the final branding can change while the underlying approach of filtering visitors, validating sessions, and selectively delivering the lure remains useful to attackers.
- [12]
ANY.RUN says an evasive phishing kit can translate into longer investigation times and unnecessary escalations for MSSPs working across multiple customer environments and security stacks.
- [13]
A visitor crosses at least three distinct hostnames before the final phishing page loads.
- [14]
ANY.RUN markets that its sandbox context ensures 30% fewer Tier 1 to Tier 2 escalations.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Device Code PhishingFollow
- Phishing kits and credential exfiltrationFollow
- Managed security servicesFollow