N0va Phishkit Steals Business Logins Through Legitimate Flows

N0va Phishkit Steals Business Logins Through Legitimate Flows

N0va phishing campaigns impersonate Microsoft Teams, SharePoint and other business tools, abuse legitimate authentication to steal access tokens and enable SSO…

A phishing kit called N0va is being used in campaigns across North America and Europe to impersonate widely used business platforms and steal account access through legitimate authentication flows, according to an analysis published by security vendor ANY.RUN. A phishing kit is a ready-made bundle of web pages and scripts that criminals use to build convincing fake login screens and capture the information victims type into them.

ANY.RUN reports that N0va activity has been observed in organizations in government, technology, consulting, healthcare, and other sectors. The attacks use lures that imitate trusted business services including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Instead of relying only on a traditional fake login page that simply collects usernames and passwords, the campaign can guide victims through real authentication flows on the legitimate platforms. This makes the interaction look more credible and helps the attacker bypass defenses that only look for obvious malware.

The attack chain described by ANY.RUN begins with a trusted-brand lure and moves through device code phishing to legitimate authentication. Device code phishing is a technique that abuses a sign-in option designed for devices that cannot show a full web browser; the victim is persuaded to approve a request or enter a code, which gives the attacker a valid token for the victim's account. After the user completes authentication, N0va can capture access tokens and refresh tokens. An access token is a short-lived proof that a user has already logged in, and a refresh token allows the attacker to obtain new access tokens without asking for the password again. The campaign can then abuse token-exchange or device-registration mechanisms to establish single sign-on (SSO) access. SSO means that one approved login grants access to many connected services, so a single stolen identity can open email, files, cloud applications, and other corporate resources.

The impact of a N0va compromise depends on the permissions of the account that is taken over, but ANY.RUN warns that the consequences can extend well beyond the initial phishing message. Attackers may use compromised accounts for payment fraud, invoice manipulation, or other financially motivated activity. Access to business applications can expose customer records, employee information, intellectual property, and confidential communications. Containment can force security teams to revoke active sessions, reset access, investigate affected systems, and restrict services while the incident is resolved. Regulated data exposure may trigger reporting requirements, investigations, contractual issues, or penalties, and a breach involving trusted company accounts can weaken customer confidence and strain relationships with partners and clients.

ANY.RUN's analysis includes several ways for security teams to investigate and respond to N0va. Its Threat Intelligence Lookup allows analysts to search for a characteristic URL pattern used by the campaign: /api/verification/init?session=*&flow=*prompt_profile=". The query surfaces matching URLs and related activity that share the same request structure, helping analysts see how the campaign appears across different submissions and infrastructure instead of treating each indicator as an isolated event. In a recent case with a Microsoft-themed lure, ANY.RUN's interactive sandbox produced the first malicious verdict in 24 seconds and exposed the full attack chain within the same session. The company says its threat intelligence is built from activity observed across more than 16,000 organizations and 700,000 security professionals. Once N0va activity is confirmed, ANY.RUN's threat intelligence feeds can deliver indicators of compromise into SIEM, SOAR, EDR, firewalls, and other security tools already used in an environment. ANY.RUN reports that organizations using its platform have cut Tier 1 investigation time by 20 percent, reduced Tier 1-to-Tier 2 escalations by 30 percent, and shortened mean time to respond (MTTR) by 21 minutes per case.

For website owners and businesses, N0va is a reminder that account security and infrastructure security are tightly linked. A compromised Microsoft or Google identity can be used to reach the same control panels, file stores, and cloud services that run a company's website and customer data. AEU-I, AEU Group's security-first IT and consulting service, helps organizations apply consistent identity and access controls across their infrastructure, which can reduce the blast radius of this kind of phishing-driven account takeover.

How to Protect Yourself

  1. If you receive an unexpected email or message asking you to sign in to Microsoft Teams, SharePoint, or a similar service, do not click the link; open the service by typing its address yourself.
  2. If you are asked to enter a code shown on another device or approve a login you did not start, stop and contact your IT team before doing anything.
  3. Turn on multi-factor authentication for your business accounts, and prefer authentication methods that resist phishing where your service offers them.
  4. Regularly review the active sessions or connected devices in your Microsoft, Google, and other business accounts, and sign out anything you do not recognize.
  5. Report suspicious login prompts or unexpected account activity to your IT or security team immediately, even if you think you already closed the page.

Terms Explained

  • phishing kit A ready-made set of web pages and scripts that criminals use to create fake login screens and harvest account details.
  • access token A short-lived digital proof that a user has already logged in, allowing a device to stay connected without re-entering a password.
  • refresh token A longer-lived credential that lets an attacker get new access tokens without knowing the victim's password.
  • single sign-on (SSO) A method that lets one approved login open several connected services at the same time.
  • device code phishing A trick that abuses a sign-in option for devices without a full browser, getting the victim to approve a request that hands the attacker a valid token.
  • indicators of compromise Signals such as malicious web addresses, file hashes, or network patterns that help security teams detect an attack.
  • SIEM A system that collects and analyzes security alerts from many parts of a company's network.
  • SOAR A platform that automates routine security tasks and helps coordinate responses to incidents.
  • EDR Software that monitors computers and servers for suspicious behavior and helps stop threats.

Related AEU services

  • AEU-I IT and security consulting