VMTech
Discuss a project

N0va phishing kit targets business identities in North America and Europe

N0va phishing kit targets business identities in North America and Europe

N0va targets business accounts through trusted authentication flows

The N0va phishkit is being used against organisations in North America and Europe, including targets in government, technology, consulting and healthcare. The campaign impersonates familiar business services and can obtain valid account access by steering victims through legitimate authentication processes rather than relying solely on a conventional credential-harvesting page.

ANY.RUN describes the risk as an identity-security problem with potentially broad consequences. Once an attacker controls a valid identity, access may extend to sensitive data, business systems and further cloud resources associated with that account. The scope depends on the victim's permissions, and the risk rises while access remains undetected.

Trusted brands and device-code phishing

N0va lures imitate Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom and Adobe Sign. By using services employees recognise, and by directing them through legitimate sign-in flows, the campaign can make an authentication request appear credible.

The attack chain identified by ANY.RUN is: trusted-brand lure, device-code phishing, legitimate authentication, capture of access and refresh tokens, token exchange or device registration, and SSO access to corporate resources. Captured tokens can be abused to reach email, files, cloud applications and other resources connected to the compromised identity.

Investigators can search for activity matching the characteristic URL pattern /api/verification/init?session=*&flow=*prompt_profile=. ANY.RUN says its Threat Intelligence Lookup can connect matching URLs with related domains, IPs, files, sandbox sessions and infrastructure, allowing analysts to assess whether an indicator belongs to a wider campaign.

Operational and business exposure

A compromised account can be used for payment fraud, invoice manipulation or other financially motivated activity. Access to business applications may also expose customer records, employee information, intellectual property and confidential communications. Containment can require teams to revoke sessions, reset access, investigate affected systems and restrict services during the response.

For organisations handling regulated data, an incident may also create reporting, investigation, contractual or penalty exposure. A breach involving trusted company accounts can damage confidence among customers, partners and clients.

Detection needs behavioural evidence

Because N0va can abuse legitimate services and authentication processes, behavioural evidence is important for validating the activity. ANY.RUN reports that an interactive sandbox session involving a Microsoft-themed N0va lure produced its first malicious verdict in 24 seconds and exposed the full attack chain in the same session.

Once activity is confirmed, the vendor recommends distributing relevant indicators to SIEM, SOAR, EDR, firewalls and other existing controls through threat-intelligence feeds. The practical business implication is to investigate suspicious device-code requests, token activity and connected infrastructure as an identity incident, then revoke affected access and extend detections across the security stack.

#cybersecurity#phishing#identitysecurity#threatintel
Open analytics
On the site 0 views
min read 4 16.09.2026
Instagram

N0va phishing kit targets business identities in North America and Europe

Open the post on Instagram ↗