N0va phishing campaign targeting North America and Europe
Campaign
Summary
Hide ▲
Show ▼
N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-account access that can expose sensitive data, business systems, and cloud resources. The operation uses familiar business-platform lures to increase trust and reduce suspicion. The resulting access can spread from a single account into broader corporate compromise.
Related Happenings
CISA and NIST issue cloud identity token guidance
Public Sector Action
H score35
First: 16.09.2026 17:00
Last: 16.09.2026 17:00
Sources 1
About this happening:
CISA and NIST issued final guidance for protecting cloud identity tokens and assertions, setting a federal cybersecurity baseline for federal agencies, cloud service...
CISA and NIST issue cloud identity token guidance
Public Sector ActionAbout this happening: CISA and NIST issued final guidance for protecting cloud identity tokens and assertions, setting a federal cybersecurity baseline for federal agencies, cloud service...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
RecruitTrap recruitment-themed phishing campaign
Campaign
H score25
First: 14.08.2026 13:57
Last: 14.08.2026 13:57
Sources 1
About this happening:
The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...
RecruitTrap recruitment-themed phishing campaign
CampaignAbout this happening: The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Timeline
-
16.09.2026 14:58 2 articles · 5d ago
N0va phishing campaign targets North America and Europe
Initial DisclosureN0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted business services and abuse legitimate authentication flows. The activity has been observed across government, technology, consulting, healthcare, and other sectors, and successful compromises can capture access and refresh tokens to establish SSO access to email, files, cloud applications, and other corporate resources.
Show sources
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security — thehackernews.com — 16.09.2026 14:58
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security — thehackernews.com — 16.09.2026 14:58