New N0va Phishkit Exploits Trusted Services for SSO Access
A new phishing kit named N0va is targeting organizations in North America and the EU, leveraging legitimate authentication flows and token capture to bypass MFA and gain persistent SSO access.

Researchers have identified a new and sophisticated phishkit dubbed N0va, which is actively targeting organizations across North America and the European Union. The kit is designed to compromise a wide range of sectors, including government, technology, consulting, and healthcare. What sets N0va apart is its method of blending into legitimate business workflows, making it particularly challenging for Security Operations Centers (SOCs) to detect and investigate.
The attack chain begins with lures that mimic widely used and trusted business services such as Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. In observed instances, a Microsoft-themed lure has been used to guide victims through a device code authentication flow. This process closely imitates legitimate Microsoft verification pages, creating a sense of familiarity and trust that encourages users to proceed without suspicion.
Once a user engages with the phishing lure and completes the authentication step, N0va is capable of capturing not just passwords, but also access and refresh tokens. The phishkit then abuses token-exchange and device-registration mechanisms. This allows attackers to establish Single Sign-On (SSO) access to corporate resources, potentially granting them persistent access even after the initial phishing interaction has concluded or the phishing page has been taken down.
This technique presents significant challenges for SOC leaders. The use of trusted brands and legitimate authentication flows means that a successful compromise can lead to a deeper level of account takeover than traditional credential theft. Attackers can gain continued access through stolen tokens, and the seemingly legitimate authentication process can create blind spots, making the activity appear less suspicious than a typical fake login page.
Furthermore, the distributed nature of the attack—involving phishing pages, authentication services, and backend infrastructure that may span different tools—can limit visibility and make it difficult for security teams to connect the dots and understand the full scope of an incident. This complexity increases the investigation effort required, as analysts may need to correlate activity across email, identity providers, browsers, and network logs to confirm a compromise.
To combat threats like N0va, organizations are advised to strengthen their defenses in several key areas. Enhancing validation processes at Tier 1 support levels, providing better threat context across investigations, and broadening detection coverage across the entire security stack are crucial. Tools that offer safe environments for reproducing phishing behavior, inspecting browser activity, and correlating disparate indicators of compromise can significantly aid SOC teams.
By providing SOC analysts with richer context, such as through interactive sandboxes and threat intelligence lookups, teams can more effectively identify the full attack chain, understand the scope of campaigns, and differentiate between isolated lures and sophisticated identity attacks. This improved visibility and context are essential for faster response times and more confident decision-making in the face of evolving phishing tactics.
The N0va phishkit underscores a growing trend where attackers are moving beyond simple credential harvesting to exploit more complex authentication mechanisms and trusted service integrations. This necessitates a shift in defensive strategies towards a more holistic approach that accounts for the entire attack lifecycle and leverages advanced tools for detection and analysis.