N0va Phishkit Exploits Trust to Breach US & EU Businesses

Security teams across North America and Europe are being warned about a phishing operation called N0va, which is targeting organizations in high-risk sectors like government, consulting, healthcare, and tech. Unlike typical phishing scams that rely on malware or fake login pages, this campaign employs authentic-looking business platform lures and hijacks legitimate authentication flows to gain access to accounts and SSO-protected systems.

How N0va Operates

N0va impersonates major business and cloud services—including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign—through phishing emails or links. Once a victim is tricked by a lure, they are guided into providing credentials or device codes via realistic authentication dialogs. At that point, attackers are able to intercept access and refresh tokens. They may also abuse token-exchange or device registration mechanisms to establish persistent Single Sign-On access to additional company systems.

The structure of a typical N0va attack chain goes like this: trusted-brand lure → device-code phishing → passage through genuine authentication → capture of tokens → abuse via SSO or device registration. This sequence lets threat actors move laterally within an organization and access cloud services, email, files, and sensitive corporate data once they gain control of an account.

The Stakes: What’s at Risk

A successful identity compromise under the N0va campaign can trigger wide-ranging damage. Examples of potential fallout include payment fraud and financial manipulation; exposure of personal, business, or intellectual property data; service interruptions; regulatory fines and compliance breaches; and erosion of trust from clients, partners, and employees.

Defensive Strategies

Because N0va abuses legitimate authorization workflows, it’s harder to spot using conventional anti-phishing techniques. Security teams are encouraged to develop visibility into behavioral indicators—such as abnormal token retrievals, unexpected device registration activity, and irregular single sign-on behavior.

Contextual threat intelligence feeds are key. Analysts should map suspicious indicators like URLs, domains, and IP addresses back to known N0va activity to determine whether they’re isolated or part of a broader campaign. ALSO, sandboxing environments enable Tier 1 analysts to follow a full attack pattern live. In one Microsoft-themed case, analysts were able to unfold the entire N0va chain within 24 seconds in a sandbox, letting them triage early without overburdening senior resources.

Teams should also integrate IOCs (indicators of compromise) into security tools such as SIEM, SOAR, EDR, and firewalls, ensuring that phishing-sourced tokens and infrastructure data observed by providers are leveraged broadly across detection and prevention systems.

Reducing dwell time—the period during which attackers roam undetected—is essential. Early detection, combined with rapid incident response informed by threat intelligence and behavioral visibility, can help organizations limit the damage when identities are compromised.

Why this matters: The N0va campaign isn’t just about breaking into accounts—it’s about how phishing is evolving. By abusing legitimate platforms and authentication protocols, attackers are bypassing many defenses designed to block obvious phishing. Enterprises now face a new paradigm where identity attacks are stealthy, sophisticated, and deeply tied into systems they trust. What security leaders should watch for next: how threat actors extend toolchains for automatic token abuse, whether N0va adopts machine learning or AI to craft personalized lures, and how regulation and technologies like Zero Trust evolve to counter rising identity threats.