N0va phishing campaign targeting North America and Europe
Campaign
Summary
Hide ▲
Show ▼
N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-account access that can expose sensitive data, business systems, and cloud resources. The operation uses familiar business-platform lures to increase trust and reduce suspicion. The resulting access can spread from a single account into broader corporate compromise.
Related Happenings
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
RecruitTrap recruitment-themed phishing campaign
Campaign
H score25
First: 14.08.2026 13:57
Last: 14.08.2026 13:57
Sources 1
About this happening:
The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...
RecruitTrap recruitment-themed phishing campaign
CampaignAbout this happening: The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Timeline
-
16.09.2026 14:58 2 articles · 2h ago
N0va phishing campaign targets North America and Europe
Initial DisclosureN0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted business services and abuse legitimate authentication flows. The activity has been observed across government, technology, consulting, healthcare, and other sectors, and successful compromises can capture access and refresh tokens to establish SSO access to email, files, cloud applications, and other corporate resources.
Show sources
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security — thehackernews.com — 16.09.2026 14:58
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security — thehackernews.com — 16.09.2026 14:58