iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Wazza is a phishing kit that, in activity reported on October 8, 2026, screened visitors through multiple routing and browser checks before showing an Adobe-themed OAuth Device Code page. The Hacker News report, based on ANY.RUN analysis, says the campaign targeted organizations in banking, government, and manufacturing across the United States, Europe, and Australia; it does not identify confirmed victims or quantify the campaign’s reach.
What the Wazza report documents
The reported activity uses a multi-stage chain rather than serving the final phishing page to every visitor. The analysis describes wildcard routing on boegl-krysl.eu, followed by a campaign check at /api/wazza-config. A host on workers.dev issues a client marker used to correlate visits. The kit then requests a short-lived signed session token through /api/mint-token.
A checking domain validates that token and browser telemetry, filtering visitors before later /r and /meline paths lead to the lure. These are details of the activity and infrastructure analyzed in the report, not a guarantee that every Wazza deployment or future campaign uses the same domains or routes. The Hacker News report on ANY.RUN’s analysis describes this routing chain.
How the Device Code lure fits in
The final reported page is styled as an Adobe authentication experience and uses OAuth Device Code authentication. The Adobe presentation is the social-engineering wrapper; the reported distinguishing feature is that layered routing and checks control who reaches it. A first URL that looks ordinary in a static review may not reveal the behavior that appears only after the sequence of requests and browser checks.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Device Code authentication is a legitimate sign-in flow in some environments, but an unexpected request to complete one can be abused to persuade a user to authorize an attacker-controlled sign-in. The report characterizes Wazza’s page as a Device Code phishing lure; it does not establish that every appearance of this flow is malicious.
Who the campaign reportedly targeted
ANY.RUN’s analysis associates the observed Wazza activity with banking, government, and manufacturing organizations in the United States, Europe, and Australia. The report provides neither a list of affected organizations nor a denominator for estimating prevalence. “Targeted” therefore describes the reported campaign focus, not proof that every organization in those sectors or regions was exposed or compromised.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The reporting does not establish who operates Wazza, how many organizations were affected, or the campaign’s success rate or volume. It does not support attributing the activity to a state actor.
Recommended Free Tools
What defenders can check
Investigate links dynamically
Because the reported page appears after routing, token, and browser checks, static URL reputation alone may miss relevant behavior. For suspicious links, use an investigation environment capable of reproducing browser interactions and observing subsequent requests. The report relies on sandbox analysis to expose gated routing, but it does not compare sandbox products.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Review time-sensitive indicators
The report recommends blocking and monitoring the domains it names and reviewing DNS or proxy logs for the reported paths. Treat those domains and paths as indicators from a specific analysis, not as a permanent or exhaustive blocklist: infrastructure can change, and the report does not establish that these indicators cover every Wazza deployment.
Check identity activity and contain suspected access
- Review identity-provider sign-in logs for unexpected Device Code events, especially around the time a user visited a suspicious link.
- For affected accounts, revoke active sessions and refresh tokens in line with your organization’s incident-response process.
- Where Device Code authentication is not needed broadly, consider restricting its use to approved users, devices, or networks. Validate the available controls against your identity configuration before changing policy.
These are response measures recommended in the report, not a guarantee that any single control prevents this or other phishing activity. ANY.RUN’s September 2026 threat coverage digest separately lists a Wazza HTTP activity rule and describes the kit as using Device Code flow; that is evidence of detection coverage, not independent confirmation of campaign scale or every routing detail. ANY.RUN’s September 2026 threat coverage digest provides that separate detection reference.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

