The record
Written from the 1 report below. Nothing here is unsourced.
- A phishing kit called N0va is targeting organizations in North America and Europe through campaigns that impersonate trusted business platforms.
- N0va imitates widely used services including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign.
- The kit guides victims through legitimate authentication flows and captures access and refresh tokens, allowing attackers to gain single sign-on access to corporate resources without obvious malware.
- Government, technology, consulting, healthcare, and other high-risk sectors have been observed among the targets.
- A successful compromise can lead to financial losses, exposure of sensitive data, operational disruption, compliance penalties, and reputational damage.
What to watch next
- Any expansion of N0va targets beyond North America and Europe, including Indian organizations.
- Detection and tracking of the campaign's characteristic URL pattern by security teams and threat intelligence tools.
- Whether token-theft-based phishing attacks spread to other phishing kits and trusted platforms.
Coverage1
1 report
English national1
All filed from India
Named United States · European Union · Adobe Sign · DocuSign · Dropbox · Google Drive · Microsoft · OneDrive · SharePoint · Zoom · ANY.RUN · N0va
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
