🪝 We are observing active PDF
#phishing campaigns impersonating
#Adobe and
#Microsoft that redirect victims to
#Wazza Kit device code phishing pages hosted on
workers.dev.
-
#MailMarshal detected phishing emails from compromised accounts containing PDF attachments with document-themed lures
- The broader campaign leverages Google Sites (
sites.google.com), Cloudflare Workers (
workers.dev), and .eu Top Level Domains to host phishing content and related infrastructure
- Wazza kit supports 19 themes via the ‘?thm=‘ URL parameter across six lure categories: file-sharing, account, document, payment, HR, cloud and brand impersonation.
- The kit validates URL patterns, including subdomain and slug checks, to selectively serve phishing content and redirect non-targets to decoy pages.
#IOCs:
beacon-surge-sync[.]workers[.]dev
beton-beton[.]eu
bike-msca[.]eu
bodi-project[.]eu
bruoth-family[.]eu
cardamomo[.]eu
coppietersrecherche[.]eu
diabetesnet[.]eu
dymowski[.]eu
euniverza[.]eu
hutspotmaken[.]eu
illuminatedminds[.]eu
jetcapital[.]eu
languagesforwork[.]eu
lesbolides[.]eu
mdiament[.]eu
nbi-training[.]eu
nellarmonia[.]eu
originalpizza[.]eu
polskaprezydencjacsr[.]eu
robologic[.]eu
safetystock[.]eu
electroloys[.]com
hacsg[.]com
sites[.]google[.]com/view/hgfdsqazxcvhjoswwqq/home
sites[.]google[.]com/view/adobe-docus/home
sites[.]google[.]com/view/miticabo/home
sites[.]google[.]com/view/ctfvygbuhgyftvbgyfpoiuytrftgyh/home
sites[.]google[.]com/view/kjvcfdswqazxcfvghjoplkjmnbvcf/home
sites[.]google[.]com/view/securespdf/home
sites[.]google[.]com/view/onwajuly/home
dv0psh-purv3w-azfn-b2c0-msauth3-m365svc-s3ntln-4zrfn3x-cntnrx[.]workers[.]dev
ssosvc-m365s-kvl-dv0pshb-s3ntln-c0mply-4zrmonx-apimgwx-evnthb[.]workers[.]dev
wndws-pip3ln-sql3-waf3-purv3-gdprsx-dfn-azfn-appsvc-0ffapx[.]workers[.]dev
purv3w3-t3ms4pp-certs-intun3-sbussvx-4zredg-siemsv-pip3ln-0ffc3[.]workers[.]dev