New “N0va” Phishing Kit Uses Trusted Apps to Hijack SSO for Organizations

A fresh phishing toolkit called N0va is targeting companies across North America and Europe, with focus on public sector bodies, tech firms, consultancies, and healthcare providers. It exploits trusted authentication systems and well-known brand lures to escalate phishing attacks beyond simple credential theft, posing a serious identity risk for security operations centers (SOCs).

How N0va Executes Its Attack

N0va begins with phishing emails or messages that mimic everyday services like Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Zoom, Adobe Sign, and Dropbox. These fake lures send users through a device code authentication process that closely resembles legitimate login flows. If successful, attackers can capture access and refresh tokens and then abuse device registration or token exchange mechanisms.

This enables attackers to establish single sign-on (SSO) access to corporate resources, which often persists even after the initial phishing page has vanished. By sidestepping conventional password-based detection, N0va makes account takeover far more subtle and long-lasting.

Why It’s a Big Deal for SOCs

Because the phishing campaign takes place within trusted services and uses valid authentication flows, it greatly complicates detection. Security teams may not notice oddities because no fake login page is involved. Traditional indicators like suspicious URLs or malformed emails often fail to catch fully connected campaigns involving backend or cloud infrastructure.

Once attackers have access and refresh tokens plus control of registered devices, they can maintain access even after remedial actions are taken. Investigations are harder, too: analysts might need to align data from email logs, network traffic, identity services, browser sessions, and cloud activity to fully map the attack chain.

How SOC Leaders Can Fight Back

Three defensive strategies are especially critical:

  • Improve frontline context by giving Tier 1 analysts tools that let them replay phishing flows in secure sandbox environments. This helps distinguish isolated lures from attacks that carry further risk, reducing false positives and unnecessary escalations.
  • Increase intelligence visibility across the organization. Threat intelligence platforms that slide from URLs or domains into infrastructure and authentication signals help SOCs see the full campaign footprint—who is targeted, how the backend is set up, and what trusted services are being mimicked.
  • Operationalize detection findings by feeding indicators of compromise (IOCs) into detection tools like SIEM, SOAR, EDR, and firewalls. When one team discovers malicious infrastructure, the rest of the organization must be able to recognize it preemptively.

By implementing these steps, teams can shrink detection gaps and dramatically cut mean time to respond (MTTR), while protecting against identity-based attacks that rely on token-based persistence.

N0va illustrates a shift where phishing no longer ends at password theft but extends to token abuse, device registration, and invisible SSO hijacking. Organizations risk prolonged exposure, even if users believe they’ve “done the right thing” by not entering credentials into suspicious forms. The key now is catching the identity compromise early—SOC leaders must focus on enriching visibility, empowering Tier 1 analysts with tools and threat context, and baking detection into every layer of the defense stack.