Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Wazza phishkit screens visitors through a multi-stage chain before serving its Adobe device-code lure

ANY.RUN says the Wazza phishkit routes visitors through a multi-stage filtering chain before serving an Adobe-themed device-code phishing page. The chain screens out automated traffic, so the first link gives banking, government and manufacturing defenders little to analyze.

The Watch · Security desk

How we use AISend a correction

What happened

  • A Cloudflare workers.dev host issues a correlation marker, and /api/mint-token then mints a short-lived signed session token for the visit.
  • check[.]boegl-krysl[.]eu validates that token against browser telemetry and drops unwanted traffic before routing the survivor on to the Adobe page.
  • The final page runs an OAuth device-code flow that goes after account authentication, not only a harvested password.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A one-shot fetch of the first link renders nothing malicious, because the page only loads once the chain accepts the token and telemetry, so point-in-time URL scanning under-reports the campaign.
  • precedent The Adobe skin is swappable, so taking down the lure page does not retire the filter-validate-then-deliver delivery, which can be re-branded against other sectors.
  • exposure Because the device-code flow targets the authenticated session rather than the password, rotating a stolen credential does not necessarily close the compromised account.
  • cost An evasive kit across many customer environments means longer investigations and more escalations for the MSSP analyst who has to clear each alert.

A visitor landing on boegl-krysl[.]eu is passed to /api/wazza-config, which checks whether the hostname belongs to a live campaign [3]. The infrastructure then calls beacon-surge-sync[...]workers[.]dev for a client marker, mints a short-lived signed token at /api/mint-token, and sends that token to check[.]boegl-krysl[.]eu, which validates it against browser telemetry and drops traffic it does not want [4][5][6]. Only visitors that clear those gates continue through boegl-krysl[.]eu/r and /meline to the Adobe page [7]. By ANY.RUN's account the visitor crosses at least three distinct hostnames before any phishing content loads [13].

ANY.RUN says a URL can look unremarkable until its behavior is reproduced in the right environment, and that the infrastructure decides whether to show the page before any social engineering starts [9][10]. A scanner that fetches the first link once, without a valid token or the expected telemetry, sees a hop that does nothing.

The final stage uses an Adobe theme and an OAuth device-code flow, which ANY.RUN says lets the operator target account authentication instead of only harvesting a password [8]. The branding is the replaceable part. ANY.RUN says the approach of filtering visitors, validating sessions, and selectively delivering the lure stays useful behind a different logo [11].

The writeup does not name a threat actor, cite a CVE, or give victim counts or dates. The attribution rests on ANY.RUN alone [1]. It does name the sectors, banking, manufacturing and government, and the geographies, the US, Europe and Australia [1].

The analysis is ANY.RUN's own, and it ends on a sales line: the company says its sandbox context delivers 30% fewer Tier 1 to Tier 2 escalations [14]. That number describes the product, not the campaign.

What to watch

  • Whether other researchers corroborate ANY.RUN's attribution and publish indicators for the boegl-krysl[.]eu and check[.]boegl-krysl[.]eu infrastructure.
  • Whether the same filtering chain reappears under non-Adobe branding against new targets.
  • Whether Cloudflare removes the beacon-surge-sync workers.dev correlation endpoint and /api/mint-token token service.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives80
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    ANY.RUN identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.

    ReportedSupportedView cited source
  2. [2]

    The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page.

    ReportedSupportedView cited source
  3. [3]

    The flow begins at wildcard landing domain boegl-krysl[.]eu, where the visitor is passed to /api/wazza-config, which checks whether the hostname belongs to an active campaign.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thehackernews.com

    1 article · October 8, 2026

    Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories