news.mlab.sh
Back to the feed
threat-intel

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

High
Summary

N0va Phishkit is a sophisticated phishing campaign targeting organizations across North America and Europe, leveraging trusted business platforms and legitimate authentication flows to gain access to corporate resources. The campaign uses lures mimicking services like Microsoft Teams, SharePoint, and Zoom, and can quickly escalate from isolated phishing events into widespread identity compromise. ANY.RUN’s Threat Intelligence Lookup helps security teams quickly determine if a suspicious indicator is part of a broader N0va campaign, while interactive sandboxing provides real-time visibility into the attack chain. Implementing these strategies can significantly reduce investigation time, minimize escalations, and improve overall incident response efficiency.

N0va Phishkit is a new and evolving phishing campaign aggressively targeting organizations in North America and Europe. The campaign utilizes deceptive lures mimicking popular business platforms, including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign, to trick users into completing legitimate authentication flows. Instead of relying on traditional fake login pages, N0va guides victims through these established processes, making the interaction appear far more credible and increasing the likelihood of success.

Successful attacks can quickly lead to a compromised identity gaining access to sensitive data, business systems, and additional cloud resources. The longer that access remains undetected, the greater the potential for wider compromise, operational disruption, and financial loss. The campaign is particularly effective because it can transform isolated phishing events into a broader identity security incident by exploiting trusted platforms and legitimate authentication mechanisms.

ANY.RUN’s Threat Intelligence Lookup is a crucial tool for security teams, enabling them to quickly determine whether a suspicious N0va indicator is part of a larger campaign. By linking related URLs, domains, IPs, files, sandbox sessions, and infrastructure, it provides analysts with the necessary context to understand the scope of activity without manually connecting every piece of the puzzle. This significantly reduces the time spent validating disconnected signals and allows analysts to focus on the most critical threats.

Interactive sandboxing further enhances visibility. ANY.RUN’s Interactive Sandbox allows Tier 1 analysts to observe the attack in real-time as it unfolds, from the initial lure and redirects to network activity and follow-on behavior. In a recent case involving a Microsoft-themed lure, the sandbox produced the first malicious verdict in 24 seconds and exposed the full attack chain within the same session, dramatically speeding up resolution times.

To bolster detection coverage, threat intelligence feeds can be integrated into SIEM, SOAR, EDR, and firewalls. ANY.RUN’s threat intelligence is derived from activity observed across 16,000+ organizations and 700,000+ security professionals, providing a broader view of emerging malicious infrastructure and recurring attack patterns. This wider detection coverage leads to faster alert enrichment and reduces the need to rediscover threats already seen elsewhere.

Ultimately, N0va highlights the ease with which phishing can escalate into a significant identity security incident. By providing teams with faster access to threat context, behavioral evidence, and fresh intelligence, organizations can minimize the time between detection and containment, reducing analyst workload and mitigating the impact of compromised access.

Read the full article at The Hacker News