# Wazza phishing kit screens visitors before delivering account lure

_Published Thursday, October 8, 2026 at 8:13 AM EDT · Security · Latest · Tier 2 — Notable_

![Wazza phishing kit screens visitors before delivering account lure — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnlTrJzuyuM3FgdyTkx-JLieOXeR9fK_hENZFrdItZ09E4ZFhk8UYOPslpbGGidTUGCDgcTHqY7wvYrThg-Hwl24MQhL63GIfmRsBLy9MJ7iDXn1XbbX1W_EgGFw9eRyT4LOJq0aoyWhmOHF3O5a9L5LcKNS1IJxQqs_UBwmOnPRmx3fXwUPpKeYdARVE/s1700-nu-rw-lo-l85-e365/anyrun.jpg)

ANY.RUN has identified a phishing kit called Wazza targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign screens visitors through multiple routing stages before showing an Adobe-themed page that seeks to trick users into completing an account-authentication action.

Its infrastructure checks whether a campaign is active, assigns a visitor marker, and creates a short-lived signed session token. It then validates that token and browser information before delivering the lure. This selective delivery can give automated security systems different content from human visitors, complicating detection. A successful authentication flow can give attackers access to accounts or sessions.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html)

---
Canonical: https://techandbusiness.org/newswire/Ur--xUF_U3vVGTtT4-Bm47
Published: 2026-10-08T12:13:41.487Z
Story chronology: 2026-10-08T10:30:00.000Z
Retrieved: 2026-10-08T14:28:39.380Z
Publisher: Tech & Business (techandbusiness.org)
