HomeSecurityN0va Phishkit targets businesses in the US and EU

N0va Phishkit targets businesses in the US and EU

A different approach to phishing is being used by the campaign dubbed N0va Phishkit, with attackers attempting to bypass traditional defenses by leveraging well-known enterprise platforms and legitimate authentication processes. The activity has been detected in organizations across North America and Europe, targeting everything from the public sector to technology, healthcare and consulting.

Article image: N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

What makes N0va unique is that it doesn’t necessarily rely on obvious malware. Instead, it aims to digital identity a user’s and exploit their existing legal rights. In this way, an attack that starts with a seemingly ordinary message can escalate to access corporate emails, files, applications, and cloud infrastructure.

N0va Phishkit – From one phishing message to the entire corporate environment

N0va's logic is based on trust exploitation. Attackers use decoys that reference popular services, such as Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign.

This approach increases the chances of success, as the user is more likely to consider a request related to a platform they use every day as normal. Phishing, therefore, does not always have to look like a simple fake login page. It can be embedded in a process that looks completely legitimate.

In some scenarios, device code phishing, whereby the victim is led to complete a real authentication process. The result is that the attack can go unnoticed by mechanisms that only look for classic fake pages or malicious files.

See also: SAP Security Patch Day September 2026: New security fixes

Token theft opens the door to SSO

After successful authentication, attackers can attempt to intercept access tokens and refresh tokens. These are tokens used by services and applications to keep a user logged in without having to constantly enter their password.

If these tokens fall into the wrong hands, the situation can become particularly serious. Attackers can attempt to exploit token exchange or device registration, gaining access through the Single Sign-On (SSO).

So, the initial phishing may just be the first step. Depending on the account privileges, the compromised identity can lead to corporate emails, documents, cloud applications, and other resources that the employee has access to.

Which organizations are being targeted?

N0va's activity has been linked to organizations from different sectors, which shows that this method is not only relevant to a specific type of business.

See also: Apple fleets: AI phishing attacks make identity security a priority

Targets include government agencies, technology companies, consulting firms, and healthcare organizations in North America and Europe. What they have in common is their extensive use of cloud services and enterprise platforms.

This is precisely what makes the threat particularly interesting: the more services are associated with a corporate identity, the greater the value of a compromised account can be.

N0va Phishkit targets businesses in the US and EU

The true cost of a compromised identity

The consequences are not limited to the loss of a username and password. A compromised account can cause financial lossesif used for payment fraud, invoice changes, or other financially motivated actions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, there is a risk of exposing customer data, employee information, intellectual property, and confidential communications. In organizations with increased regulatory obligations, such a breach can also create reporting requirements, legal issues, or compliance problems.

Finally, there are the operational costs. The IT and security team may need to terminate active sessions, reset permissions, review endpoint and cloud logs, and temporarily restrict access to services. At the same time, a serious breach can impact customer and partner trust.

Why threat intelligence is critical

Countering N0va requires more than just blocking a suspicious URL. Security teams must be able to connect different indicators, such as domains, URLs, IPs, files, and infrastructure, to determine whether an incident is part of a broader campaign.

This approach allows analysts to assess risk more quickly and avoid investigating each suspicious event as an isolated case.

Threat intelligence and interactive sandboxing tools can also provide insight into the behavior of an attack in real time. According to ANY.RUN, in a recent case involving N0va, the sandbox provided the first indication of malicious activity within 24 seconds and revealed the attack chain during the same session.

From detection to broader defense

The value of analytics doesn’t stop at identifying an incident. New indicators can be integrated into SIEM, SOAR, EDR, firewalls, and other security systemsso an organization can identify similar patterns in future attacks.

According to ANY.RUN, its platform is based on activity from more than 16,000 organizations and 700,000 security professionals, offering a broader framework for identifying malicious infrastructure and recurring techniques.

See also: How does two-factor authentication (2FA) enhance security?

For businesses, however, technology is only one part of the defense. Equally important is employee education, implementing phishing-resistant MFA where available, restricting user privileges, and constantly monitoring for unusual connections and new devices.

N0va Phishkit targets businesses in the US and EU

N0va shows the new reality of phishing

This particular campaign highlights a significant change in the cyberattack landscape: attackers don't always need to install malware to gain access. They can steal a user's identity and then move through legitimate services and authentication mechanisms.

For this reason, protecting an organization cannot rely solely on detecting malicious files. Monitoring account behavior, authentication events, tokens, and device changes is becoming increasingly important.

As enterprise environments move more to the cloud and SSO connects more and more services, digital identity is becoming a top target for cybercriminals. N0va is a prime example of why early detection and rapid response can make the difference before a stolen identity turns into a widespread business breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS