Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Summary
A new phishing kit named Wazza has been identified, targeting banking, government, and manufacturing organizations in the US, EU, and Australia. This phishkit goes beyond traditional credential harvesting by incorporating advanced features like filtering, session management, and traffic controls within its delivery infrastructure.
IFF Assessment
The emergence of sophisticated phishing kits like Wazza, which include advanced functionalities, poses a significant threat to organizations by increasing the effectiveness of phishing attacks.
Defender Context
Defenders need to be aware of evolving phishing kit capabilities beyond simple fake login pages. Organizations should enhance their defenses against sophisticated phishing campaigns by implementing advanced email filtering, user awareness training on session hijacking and credential theft, and robust incident response plans.