The emergence of the N0va phishing kit targeting organisations across the United States and Europe illustrates a significant evolution in identity-based cyberattacks, where criminals increasingly focus on exploiting legitimate authentication workflows rather than simply stealing usernames and passwords through conventional phishing pages. The campaign has been observed targeting organisations across government, technology, consulting, healthcare and other sectors, using familiar business platforms and trusted cloud services to make malicious interactions appear legitimate. What makes this approach particularly concerning is that the attacker may not need to compromise the user's password or install malicious software on the endpoint, because the attack is designed to manipulate the authentication process itself and obtain tokens that provide access to corporate applications. The distinction matters because many organisations have invested heavily in password protection, multi-factor authentication and endpoint security, yet identity attacks continue evolving toward mechanisms that exploit the trust established after authentication has already succeeded. 

N0va uses phishing lures impersonating widely adopted business platforms, including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom and Adobe Sign, creating a convincing environment in which employees believe they are responding to ordinary business communications. A document-sharing notification, collaboration invitation or electronic signature request can appear entirely consistent with a user's daily responsibilities, particularly when the organisation already relies on these services for routine operations. Instead of directing victims only to a counterfeit login form, the campaign can guide them through legitimate authentication flows, including device code authentication, which makes the interaction more difficult to distinguish from a genuine sign-in process. This demonstrates why modern phishing cannot be identified solely by checking whether the login page belongs to the expected service, because the authentication page itself may be genuine while the transaction being authorised benefits the attacker.

The abuse of device code authentication is particularly important because the mechanism was originally designed to simplify authentication for devices that cannot conveniently display a full login interface, such as smart televisions, command-line applications and other limited-input systems. In a legitimate workflow, a device requests an authorisation code, and the user enters that code through a trusted authentication page to approve access for the requesting application or device. Attackers can exploit this separation by initiating an authentication request themselves and persuading the victim to complete the authorisation step using the attacker's code. The user may enter credentials and complete multi-factor authentication on a legitimate identity-provider website without realising that they are authorising an attacker-controlled session rather than their own intended activity. This creates a dangerous situation in which every individual step may appear technically legitimate, while the overall sequence results in an unauthorised party obtaining access.

The role of OAuth access and refresh tokens makes the attack considerably more serious than ordinary password harvesting. An access token provides authorisation to use particular resources for a defined period, while a refresh token may allow an application to obtain additional access tokens without repeatedly asking the user to authenticate, subject to the identity provider's policies and token validity rules. N0va's reported attack chain can capture these tokens and abuse token-exchange or device-registration mechanisms to establish single sign-on access to corporate resources. Depending on the permissions granted and the effectiveness of additional access controls, this may expose email, files, cloud applications and other business systems associated with the compromised identity. An attacker who obtains usable authentication tokens may therefore maintain access without possessing the victim's password, making password resets alone potentially insufficient to contain the incident.

This attack also reveals an important limitation in treating multi-factor authentication as the final boundary of identity security. MFA remains an essential protection against credential theft, password spraying and many forms of account takeover, but it cannot guarantee that every authentication transaction being approved by a user is legitimate. In device code phishing, the victim may successfully complete the MFA challenge while unknowingly authorising a session initiated by the attacker. The weakness is not necessarily in the MFA technology itself but in the context surrounding the authentication request, because the user may not understand which application or device is requesting access and why that approval is necessary. Organisations therefore need to complement MFA with phishing-resistant authentication where applicable, carefully governed device code flows, application consent controls and security policies that evaluate the context of access rather than simply recording whether an authentication challenge succeeded.

The potential business impact extends beyond the initial account compromise because enterprise identities frequently provide access to multiple applications through single sign-on. A compromised identity may be connected to corporate email, document repositories, collaboration platforms, customer management systems and internal business applications, meaning attackers can potentially move between services using credentials and authorisations that the environment already recognises. The actual consequences depend on the account's permissions and the controls implemented by the organisation, but possible outcomes include theft of confidential documents, exposure of customer records, business email compromise, invoice manipulation and access to additional cloud resources. This demonstrates why the security impact of identity compromise should be assessed according to the applications and information accessible through the affected account rather than treating every stolen token as an isolated authentication event.

Business email compromise becomes particularly relevant when attackers obtain access to an employee's legitimate mailbox through a valid session. Instead of sending a suspicious message from an unfamiliar domain, the attacker may potentially communicate from an established corporate identity, inspect existing conversations and construct fraudulent payment instructions that match the language and context of ongoing business transactions. The credibility of the attack increases because the message can originate from an account that colleagues, customers and suppliers already trust. Similar risks arise when compromised identities provide access to document-sharing platforms, where attackers may inspect confidential files or distribute further phishing lures through authentic collaboration workflows. Identity compromise can therefore become a multiplier that supports additional attacks against people who were not targeted during the original phishing attempt.

The campaign also demonstrates why modern security monitoring cannot rely exclusively on malicious file detection or conventional phishing signatures. N0va can exploit legitimate authentication endpoints and cloud services, meaning there may be no suspicious executable, malicious attachment or obviously fraudulent login page to identify. Security operations teams need visibility into device code authentication events, OAuth token issuance, application consent, token exchange, device registration and subsequent access to corporate resources. Unusual authentication flows, unexpected applications requesting access, unfamiliar device registrations and sudden access to services that a user does not ordinarily use should be correlated rather than evaluated as unrelated events. A successful login should establish only that authentication occurred, not that every subsequent activity using the resulting session is automatically legitimate.

The use of numerous trusted business brands also makes domain-based detection more complicated. A phishing campaign may impersonate different platforms depending on the recipient's role, organisation or expected workflow, while changing URLs and infrastructure as detection improves. Security teams that respond by blocking only one reported phishing domain may stop an individual campaign instance while missing related infrastructure or subsequent variants. Threat intelligence becomes more useful when analysts identify relationships between suspicious URLs, redirect patterns, authentication flows, infrastructure and observed behaviour. Understanding the broader attack technique allows defenders to develop detection rules that remain useful even when attackers replace their domains or change the visual appearance of phishing pages.

Endpoint and network security controls continue to provide important defensive opportunities, but their effectiveness increasingly depends on understanding context. A user visiting a legitimate Microsoft authentication endpoint is not inherently suspicious, and a browser exchanging tokens with a recognised identity provider may be performing an ordinary business function. The warning signs may instead emerge from the sequence of activity, including an unexpected authentication prompt originating from an unfamiliar website, an unusual device code flow and subsequent access to corporate applications from an unrecognised session. Correlating web activity, identity-provider events, device posture and application access can help distinguish an ordinary authentication transaction from one in which the legitimate user has been manipulated into authorising attacker-controlled access.

Organisations should also reconsider whether device code authentication is necessary for every employee and application. The feature serves legitimate purposes, particularly for devices and tools without convenient interactive login capabilities, but it should not automatically be available without appropriate governance in environments where its business use is limited. Administrators can evaluate available identity-provider policies to restrict or block device code authentication where supported, require additional controls for sensitive applications and monitor its usage for unexpected patterns. The objective is not to disable useful authentication functionality indiscriminately, but to reduce exposure to workflows that attackers can exploit when the organisation has no legitimate reason to permit them.

Application consent and OAuth permission governance deserve similar attention because an authentication flow can establish access that extends beyond a single interactive session. Organisations should maintain visibility into which applications have been authorised, what permissions they possess, who approved them and whether those permissions remain necessary. Excessive consent privileges can magnify the damage of a successful phishing attack by giving a compromised application access to resources unrelated to its intended purpose. Least-privilege principles should therefore apply to both human accounts and application identities, with sensitive permissions requiring additional approval and unused authorisations being removed when no longer required.

The incident-response process for N0va must also extend beyond telling the affected employee to change their password. If an attacker has obtained valid access or refresh tokens, organisations may need to revoke active sessions, invalidate associated tokens, investigate suspicious application grants and review newly registered devices or authentication methods. Security teams should examine the activities performed through the compromised identity to determine whether the attacker accessed email, downloaded files, modified permissions or established additional persistence. Password rotation may still be appropriate, particularly if credential exposure is suspected, but containment must address every mechanism through which the attacker can continue accessing the environment. Otherwise, an organisation may believe that the account has been secured while an existing token or authorised application continues providing access.

User awareness also needs to evolve because the traditional advice to verify the website address before entering a password is not sufficient against attacks that deliberately use authentic authentication pages. Employees should understand that an unexpected request to enter a device code or approve an application can be suspicious even when it appears on a legitimate Microsoft or other identity-provider website. Training should focus on recognising the business context of authentication requests, including whether the user actually initiated the action, whether the application requesting access is expected and whether the approval is necessary for the task being performed. Users should be encouraged to report unexpected authentication prompts rather than treating every legitimate-looking login page as evidence that the underlying transaction is safe.

For security leaders, the N0va campaign reinforces the need to measure identity security through more than MFA deployment rates and password-policy compliance. Those metrics remain useful, but they do not fully address attacks that exploit legitimate authorisation flows or misuse tokens after authentication. A mature identity-security programme should consider visibility into token issuance and usage, device registration, application consent, privileged access, session revocation and abnormal behaviour across connected SaaS platforms. Organisations should also evaluate whether their security teams can reconstruct the full sequence of an identity attack, from the initial phishing lure through authentication and subsequent resource access, because fragmented logging can allow a connected intrusion to appear as a collection of unrelated routine events.

The broader cybersecurity lesson is that attackers are increasingly targeting the trust relationships connecting users, applications, devices and cloud platforms rather than focusing exclusively on the password itself. A legitimate authentication page can be used within a malicious workflow, an MFA challenge can be completed by the genuine user while benefiting the attacker, and a valid access token can subsequently be used for unauthorised activity. Security therefore needs to evaluate not only whether a request contains valid credentials but also how those credentials were obtained, which session or device is using them, what permissions they provide and whether the resulting actions are consistent with legitimate business activity.

Ultimately, N0va demonstrates that identity has become one of the most important attack surfaces in the modern enterprise. As organisations rely increasingly on cloud applications, collaboration platforms and single sign-on, a compromised identity can provide access to multiple valuable resources without requiring the attacker to exploit each application individually. Protecting that environment requires a coordinated approach combining phishing-resistant authentication, controlled authorisation workflows, token security, device trust, contextual access policies, behavioural monitoring and rapid session revocation. The objective is no longer simply to prevent an attacker from learning a user's password, but to ensure that authentication and authorisation cannot be manipulated into granting access to someone who was never entitled to receive it.


N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud

Source: N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security via The Hacker News — published 16 Sep 2026.