A phishing campaign called N0va is targeting organizations across North America and Europe by impersonating trusted business services and exploiting legitimate authentication systems, according to a report published by The Hacker News this week. The attacks have been observed across government, technology, consulting, healthcare, and other high-risk sectors. When successful, these phishing attempts allow attackers to capture valid credentials and gain access to corporate accounts without deploying traditional malware, making detection significantly harder.

The N0va campaign imitates widely used business platforms including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Rather than simply presenting a fake login page, the campaign guides victims through legitimate authentication flows, making the interaction appear credible. After a user completes authentication, N0va captures access and refresh tokens and abuses token-exchange or device-registration mechanisms to establish single sign-on access. This grants attackers entry to email, files, cloud applications, and other corporate resources tied to the compromised identity. In a recent case involving a Microsoft-themed lure tested in ANY.RUN's Interactive Sandbox, the system produced the first malicious verdict in 24 seconds and exposed the full attack chain within the same session.

According to the report, organizations using ANY.RUN have cut Tier 1 investigation time by 20%, reduced Tier 1-to-Tier 2 escalations by 30%, and shortened mean time to respond by 21 minutes per case when dealing with identity threats. The report notes that related N0va activity can be traced using a characteristic URL pattern through ANY.RUN's Threat Intelligence Lookup: `url:"/api/verification/init\?session=*&flow=*prompt_profile="`. This query surfaces matching URLs and related activity that share the same request structure, helping analysts move beyond a single indicator and see how the campaign appears across different submissions and infrastructure.

The report explains that identity compromise can quickly escalate into a business-wide incident once attackers reach systems and data tied to that account. Financial losses may result from payment fraud or invoice manipulation. Access to business applications can expose customer records, employee information, intellectual property, and confidential communications. Containment can force teams to revoke sessions, reset access, investigate affected systems, and restrict services while the incident is resolved. Exposure of regulated data may trigger reporting requirements, investigations, contractual issues, or penalties. A breach involving trusted company accounts can weaken customer confidence and strain relationships with partners and clients.

The report recommends that security teams use threat intelligence lookup to quickly determine whether a suspicious N0va indicator is isolated or connected to a broader campaign, equip analysts with behavioral evidence through interactive sandbox tools, and turn confirmed N0va intelligence into broader detection coverage by feeding indicators into SIEM, SOAR, EDR, firewalls, and other security tools. ANY.RUN's threat intelligence is built from activity observed across 16,000-plus organizations and 700,000-plus security professionals, giving teams a broader view of emerging malicious infrastructure and recurring attack patterns. The report emphasizes that N0va is harder to contain when activity is treated as a series of isolated phishing events rather than a coordinated campaign. Organizations that don't recognize the scope of sophisticated phishing operations may find themselves managing containment costs long after the initial breach, while competitors with stronger identity controls avoid the same exposure entirely.