Advisory
Published 2026-09-16
Verified 2026-09-19

N0va phishkit: US/EU business phishing abusing legitimate auth flows (ANY.RUN / THN)

The Hacker News (16 September 2026), citing ANY.RUN threat-intelligence material, describes N0va — a phishing kit targeting organisations in North America and Europe across government, technology, consulting, healthcare and related sectors. Campaigns impersonate trusted services and abuse legitimate authentication flows so successful hits yield valid account access without obvious malware. ANY.RUN publishes a characteristic URL pattern for TI Lookup: /api/verification/init?session=*&flow=*prompt_profile=. Impact once an identity is taken includes payment fraud, data exposure, and lateral move into cloud apps depending on the user’s privileges. Wire-primary until a vendor/CISA/ACSC primary notice appears. Australian operators: watch for lookalike SSO / MFA-prompt pages and enforce phishing-resistant MFA where possible.

Product
Enterprise identity / SSO / cloud login flows (phishing kit, not a product CVE)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Phishing-resistant MFA; conditional access / impossible-travel alerts; user reporting of unexpected MFA prompts; hunt ANY.RUN URL pattern in web proxy logs.

Primary: The Hacker News — N0va phishkit (16 Sep 2026)

tech identity cloud