Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Norway’s sovereign wealth fund profits from Israeli holdings amid genocide | Business and Economy News

    September 16, 2026

    DoJ accuses Russia of trying to kill Ukraine allies in US and Europe

    September 16, 2026

    Reform-linked thinktank ‘to call for big tax cuts for the rich’ | Reform UK

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Norway’s sovereign wealth fund profits from Israeli holdings amid genocide | Business and Economy News
    • DoJ accuses Russia of trying to kill Ukraine allies in US and Europe
    • Reform-linked thinktank ‘to call for big tax cuts for the rich’ | Reform UK
    • SK Hynix reportedly in talks with Intel to build memory chips in US
    • N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
    • FCA Guidance Lands Two Weeks Before UK Crypto Authorization Window Opens
    • Alzheimer’s damage may begin outside the brain
    • For the first time, Congolese NGO to manage a DRC protected area
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.

    From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud resources. The longer that access goes unnoticed, the greater the potential for wider compromise, operational disruption, and financial loss.

    N0va Is Reaching Organizations Across High-Risk Sectors

    N0va activity has been observed across organizations in government, technology, consulting, healthcare, and other sectors in North America and Europe. Its use of trusted business platforms and cloud services makes the campaign relevant across a wide range of organizations.

    N0va phishing campaign attack details

    Related activity can be traced in ANY.RUN’s Threat Intelligence Lookup using a characteristic N0va URL pattern:

    url:”/api/verification/init?session=*&flow=*prompt_profile=”

    ANY.RUN’s TI Lookup provides broader context on N0va activity for deeper investigations

    The query surfaces matching URLs and related activity that share the same request structure, helping analysts move beyond a single indicator and see how the campaign appears across different submissions and infrastructure.

    Give your team the context to investigate faster, prioritize the right threats, and respond with greater confidence.

    Cut MTTR by 21 Mins per Case

    What a N0va Compromise Can Cost the Business

    Identity compromise can quickly become a business-wide incident once attackers reach systems and data tied to that account. The impact depends on the user’s permissions, but the consequences can extend well beyond the initial phishing event.

    • Financial losses: Attackers may use compromised accounts for payment fraud, invoice manipulation, or other financially motivated activity.
    • Sensitive data exposure: Access to business applications can put customer records, employee information, intellectual property, and confidential communications at risk.
    • Operational disruption: Containment can force teams to revoke sessions, reset access, investigate affected systems, and restrict services while the incident is resolved.
    • Compliance and legal consequences: Exposure of regulated data may trigger reporting requirements, investigations, contractual issues, or penalties.
    • Reputational damage: A breach involving trusted company accounts can weaken customer confidence and strain relationships with partners and clients.

    How N0va Uses Familiar Business Platforms to Steal Access

    N0va uses phishing lures that imitate widely used business platforms, including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Instead of relying only on a traditional fake login page, the campaign can guide victims through legitimate authentication flows, making the interaction appear more credible.

    See sandbox session with Microsoft-themed N0va lure

    Microsoft-themed N0va phishing page exposed in ANY.RUN’s interactive sandbox

    After the user completes authentication, N0va can capture access and refresh tokens and abuse token-exchange or device-registration mechanisms to establish SSO access. This can give attackers access to email, files, cloud applications, and other corporate resources connected to the compromised identity.

    In short, the attack chain looks like this:

    Trusted-brand lure → Device code phishing → Legitimate authentication → Access and refresh token capture → Token exchange / device registration → SSO access to corporate resources

    How Security Teams Can Reduce the Risk from N0va

    N0va is harder to contain when activity is treated as a series of isolated phishing events. Security teams need enough context to understand whether an indicator belongs to the wider campaign, confirm how the attack behaves, and push that intelligence into the tools already protecting the environment.

    1. Give Your Team the Context to Prioritize N0va Risk

    Threat Intelligence Lookup helps security teams quickly determine whether a suspicious N0va indicator is isolated or connected to a broader campaign. By linking related URLs, domains, IPs, files, sandbox sessions, and infrastructure, it gives analysts the context they need to understand the scope of activity without piecing every connection together manually.

    TI Lookup connects relevant sandbox sessions to provide context on recent N0va activity

    That means less time spent validating disconnected signals and more attention on the activity that poses the greatest risk. For security leaders, it supports faster prioritization, more efficient use of analyst time, and clearer decisions about where investigation and response resources should go first.

    2. Equip Your SOC With Behavioral Evidence

    N0va can abuse legitimate authentication flows and trusted business services, making behavioral visibility critical for confirming what is actually happening. With ANY.RUN’s Interactive Sandbox, Tier 1 analysts can observe the attack in real time as it unfolds, from the initial lure and redirects to network activity and follow-on behavior.

    In a recent N0va case involving a Microsoft-themed lure, the sandbox produced the first malicious verdict in 24 seconds and exposed the full attack chain within the same session. That speed helps Tier 1 analysts resolve more cases independently instead of escalating every suspicious event to more experienced team members.

    Only 24 seconds required from analysts to expose the full attack chain of N0va inside interactive sandbox

    For security leaders, this means higher Tier 1 capacity, fewer unnecessary escalations to Tier 2, and more senior analyst time available for the incidents that genuinely require deeper investigation.

    3. Turn N0va Intelligence into Broader Detection Coverage

    Once N0va activity is confirmed, the next step is making sure those findings strengthen detection beyond a single case. Threat Intelligence Feeds can bring fresh indicators and threat data into SIEM, SOAR, EDR, firewalls, and other security tools already used across the environment.

    Fresh, actionable IOCs delivered into your existing security stack

    ANY.RUN’s threat intelligence is built from activity observed across 16,000+ organizations and 700,000+ security professionals, giving teams a broader view of emerging malicious infrastructure and recurring attack patterns. For security leaders, that means wider detection coverage, faster enrichment of future alerts, and less time spent rediscovering threats that have already been seen elsewhere.

    Build a Faster Response to Identity Threats

    N0va shows how easily phishing can turn into a broader identity security incident when attackers abuse trusted platforms and legitimate authentication flows. Giving teams faster access to threat context, behavioral evidence, and fresh intelligence helps reduce the time between detection and containment.

    With ANY.RUN, organizations have cut Tier 1 investigation time by 20%, reduced Tier 1-to-Tier 2 escalations by 30%, and shortened MTTR by 21 minutes per case. That means more incidents resolved at the first line, less pressure on senior analysts, and less time for compromised access to develop into a larger business problem.

    Stop identity threats from consuming analyst time, senior expertise, and incident response capacity.

    Accelerate Threat Response

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    Businesses challenge Identity N0va Phishkit Security targets
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft says Copilot buttons still missing in classic Outlook

    Critical ScreenConnect flaw now actively exploited in attacks

    Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Windows Server 2022 reaches end of mainstream support next month

    Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

    Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Norway’s sovereign wealth fund profits from Israeli holdings amid genocide | Business and Economy News

    September 16, 2026

    DoJ accuses Russia of trying to kill Ukraine allies in US and Europe

    September 16, 2026

    Reform-linked thinktank ‘to call for big tax cuts for the rich’ | Reform UK

    September 16, 2026

    SK Hynix reportedly in talks with Intel to build memory chips in US

    September 16, 2026
    Latest Posts

    What is Trump Media’s Truth API and why is it controversial?

    August 4, 2026

    How ProPublica Tested Hundreds of Omaha Homes for Lead — ProPublica

    August 4, 2026

    Golar LNG raises $600 million loan with FLNG business expansion in mind

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Norway’s sovereign wealth fund profits from Israeli holdings amid genocide | Business and Economy News

    September 16, 2026

    DoJ accuses Russia of trying to kill Ukraine allies in US and Europe

    September 16, 2026

    Reform-linked thinktank ‘to call for big tax cuts for the rich’ | Reform UK

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.