🚨 We identified #Wazza, a new phishkit targeting banking, manufacturing, and government orgs in the US, Europe, and Australia. It evades automated detection by routing victims through campaign checks and anti-bot filters before sending them to an Adobe-themed Device Code #phishing page.
See each stage unfold in #ANYRUN Sandbox and gather #IOCs: https://app.any.run/tasks/be1f83a0-742a-42de-afe4-c20110ef667f/?utm_source=mastodon&utm_medium=post&utm_campaign=wazza_phishkit&utm_term=230926&utm_content=linktoservice#cybersecurity #infosec
#iocs
3 posts · Last used 14d
Replying to
🚨 #Wazza phishkit routing flow:
1️⃣ *[.]boegl-krysl[.]eu — unique wildcard landing.
2️⃣ /api/wazza-config — checks whether the hostname belongs to an active campaign.
3️⃣ beacon-surge-sync[...]workers[.]dev — issues a client marker to correlate the visit.
4️⃣ /api/mint-token — creates a short-lived signed session token.
5️⃣ check[.]boegl-krysl[.]eu — validates the token and browser telemetry, filters unwanted traffic.
6️⃣ boegl-krysl[.]eu/r ➡️️ /meline — after the anti-bot check, the victim is sent through two intermediate redirect endpoints to the final Adobe-themed Device Code phishing landing page.
🔍 Pivot from #IOCs and subscribe to query updates to proactively track evolving activity: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=wazza_phishkit&utm_content=linktotilookup&utm_term=230926#%7B%22query%22:%22threatName:%5C%22wazza%5C%22%22,%22dateRange%22:90%7D
🚨 𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿 𝗖𝟮 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝗖𝗮𝘂𝗴𝗵𝘁 𝗼𝗻 𝗮 𝗟𝗶𝘃𝗲 𝗦𝘆𝘀𝘁𝗲𝗺. Interactive analysis let us capture what static detonation misses ⚠️
𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱 𝘁𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴: 𝗚𝗲𝗿𝗺𝗮𝗻𝘆 𝗮𝗻𝗱 𝗨𝗞 ❗️ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT ➡️ exo.exe dropper ➡️ Lenovo FnHotkeyUtility.exe ➡️ spkvol.dll sideloading ➡️ Rust loader ➡️ In-memory OVERLORD RAT.
🔥 The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory execution, encrypted C2, and active data exfiltration.
1️⃣ we.exe connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands hidden in HTML comments and a spoofed porsche[.]com Host header.
2️⃣ exo.exe unpacks to C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo binary, sideloads spkvol.dll, and delivers a fileless overlord-client Go agent.
📌 OVERLORD connects to lord[.]kirkdridebridge[.]com:5173 over mTLS-encrypted C2. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration.
Observed capabilities include remote access, HVNC, keylogging, audio recording, SOCKS proxying, file management, browser/messenger/wallet data theft, and Solana drainer activity.
👨💻 See the full execution chain and collect #IOCs:
https://app.any.run/tasks/926b4df0-e4c6-4250-be8f-6a4fdc845916/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoservice&utm_term=220726
⚡️ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoenterpriselanding&utm_term=220726#cybersecurity #infosec
You've seen all posts
