Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

The Hacker News by The Hacker News
September 16, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.

From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud resources. The longer that access goes unnoticed, the greater the potential for wider compromise, operational disruption, and financial loss.

N0va Is Reaching Organizations Across High-Risk Sectors

N0va activity has been observed across organizations in government, technology, consulting, healthcare, and other sectors in North America and Europe. Its use of trusted business platforms and cloud services makes the campaign relevant across a wide range of organizations.

N0va phishing campaign attack details

Related activity can be traced in ANY.RUN’s Threat Intelligence Lookup using a characteristic N0va URL pattern:

url:”/api/verification/init?session=*&flow=*prompt_profile=”

ANY.RUN’s TI Lookup provides broader context on N0va activity for deeper investigations

The query surfaces matching URLs and related activity that share the same request structure, helping analysts move beyond a single indicator and see how the campaign appears across different submissions and infrastructure.

Give your team the context to investigate faster, prioritize the right threats, and respond with greater confidence.

Cut MTTR by 21 Mins per Case

What a N0va Compromise Can Cost the Business

Identity compromise can quickly become a business-wide incident once attackers reach systems and data tied to that account. The impact depends on the user’s permissions, but the consequences can extend well beyond the initial phishing event.

  • Financial losses: Attackers may use compromised accounts for payment fraud, invoice manipulation, or other financially motivated activity.
  • Sensitive data exposure: Access to business applications can put customer records, employee information, intellectual property, and confidential communications at risk.
  • Operational disruption: Containment can force teams to revoke sessions, reset access, investigate affected systems, and restrict services while the incident is resolved.
  • Compliance and legal consequences: Exposure of regulated data may trigger reporting requirements, investigations, contractual issues, or penalties.
  • Reputational damage: A breach involving trusted company accounts can weaken customer confidence and strain relationships with partners and clients.

How N0va Uses Familiar Business Platforms to Steal Access

N0va uses phishing lures that imitate widely used business platforms, including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Instead of relying only on a traditional fake login page, the campaign can guide victims through legitimate authentication flows, making the interaction appear more credible.

See sandbox session with Microsoft-themed N0va lure

Microsoft-themed N0va phishing page exposed in ANY.RUN’s interactive sandbox

After the user completes authentication, N0va can capture access and refresh tokens and abuse token-exchange or device-registration mechanisms to establish SSO access. This can give attackers access to email, files, cloud applications, and other corporate resources connected to the compromised identity.

In short, the attack chain looks like this:

Trusted-brand lure → Device code phishing → Legitimate authentication → Access and refresh token capture → Token exchange / device registration → SSO access to corporate resources

How Security Teams Can Reduce the Risk from N0va

N0va is harder to contain when activity is treated as a series of isolated phishing events. Security teams need enough context to understand whether an indicator belongs to the wider campaign, confirm how the attack behaves, and push that intelligence into the tools already protecting the environment.

1. Give Your Team the Context to Prioritize N0va Risk

Threat Intelligence Lookup helps security teams quickly determine whether a suspicious N0va indicator is isolated or connected to a broader campaign. By linking related URLs, domains, IPs, files, sandbox sessions, and infrastructure, it gives analysts the context they need to understand the scope of activity without piecing every connection together manually.

TI Lookup connects relevant sandbox sessions to provide context on recent N0va activity

That means less time spent validating disconnected signals and more attention on the activity that poses the greatest risk. For security leaders, it supports faster prioritization, more efficient use of analyst time, and clearer decisions about where investigation and response resources should go first.

2. Equip Your SOC With Behavioral Evidence

N0va can abuse legitimate authentication flows and trusted business services, making behavioral visibility critical for confirming what is actually happening. With ANY.RUN’s Interactive Sandbox, Tier 1 analysts can observe the attack in real time as it unfolds, from the initial lure and redirects to network activity and follow-on behavior.

In a recent N0va case involving a Microsoft-themed lure, the sandbox produced the first malicious verdict in 24 seconds and exposed the full attack chain within the same session. That speed helps Tier 1 analysts resolve more cases independently instead of escalating every suspicious event to more experienced team members.

Only 24 seconds required from analysts to expose the full attack chain of N0va inside interactive sandbox

For security leaders, this means higher Tier 1 capacity, fewer unnecessary escalations to Tier 2, and more senior analyst time available for the incidents that genuinely require deeper investigation.

3. Turn N0va Intelligence into Broader Detection Coverage

Once N0va activity is confirmed, the next step is making sure those findings strengthen detection beyond a single case. Threat Intelligence Feeds can bring fresh indicators and threat data into SIEM, SOAR, EDR, firewalls, and other security tools already used across the environment.

Fresh, actionable IOCs delivered into your existing security stack

ANY.RUN’s threat intelligence is built from activity observed across 16,000+ organizations and 700,000+ security professionals, giving teams a broader view of emerging malicious infrastructure and recurring attack patterns. For security leaders, that means wider detection coverage, faster enrichment of future alerts, and less time spent rediscovering threats that have already been seen elsewhere.

Build a Faster Response to Identity Threats

N0va shows how easily phishing can turn into a broader identity security incident when attackers abuse trusted platforms and legitimate authentication flows. Giving teams faster access to threat context, behavioral evidence, and fresh intelligence helps reduce the time between detection and containment.

With ANY.RUN, organizations have cut Tier 1 investigation time by 20%, reduced Tier 1-to-Tier 2 escalations by 30%, and shortened MTTR by 21 minutes per case. That means more incidents resolved at the first line, less pressure on senior analysts, and less time for compromised access to develop into a larger business problem.

Stop identity threats from consuming analyst time, senior expertise, and incident response capacity.

Accelerate Threat Response

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.





Source link

The Hacker News

The Hacker News

Next Post

Tech companies under fire as Europe proposes social media ban for under-15s | Computer Weekly

Recommended.

⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More

⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More

December 15, 2025
Stocks making the biggest moves premarket: Delta Air Lines, WK Kellogg, PTC, AMD and more

Stocks making the biggest moves premarket: Delta Air Lines, WK Kellogg, PTC, AMD and more

July 10, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

April 2, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio