"N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows," according to ANY.RUN's reporting.
How N0va's attack chain works
ANY.RUN's analysis lays out a compact but potent sequence that converts a routine phishing click into persistent, single-sign-on (SSO) access. The campaign uses trusted-brand lures that push victims into a device code phishing flow. Once a user follows the steps and completes legitimate authentication, the attacker can capture access and refresh tokens. The captured tokens are then abused via token-exchange or device-registration mechanisms to establish SSO access to corporate resources.
Summarized in the source material, the attack chain is: Trusted-brand lure → Device code phishing → Legitimate authentication → Access and refresh token capture → Token exchange / device registration → SSO access to corporate resources.
Which platforms and sectors are affected
N0va deliberately impersonates widely used business and collaboration platforms to increase credibility. The source lists Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign as examples of services used in the lures. Because these are common across enterprises, ANY.RUN warns the campaign is relevant to a broad set of organizations.
Observed activity spans government, technology, consulting, healthcare, and other sectors across North America and Europe, making it a cross-sector risk rather than one confined to a narrow niche.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat a N0va compromise can cost the business
ANY.RUN outlines five concrete consequence categories once a compromised identity is leveraged inside an environment:
- Financial losses: attackers may use compromised accounts for payment fraud, invoice manipulation, or other financially motivated activity.
- Sensitive data exposure: access to business applications can put customer records, employee information, intellectual property, and confidential communications at risk.
- Operational disruption: containment can force teams to revoke sessions, reset access, investigate affected systems, and restrict services while the incident is resolved.
- Compliance and legal consequences: exposure of regulated data may trigger reporting requirements, investigations, contractual issues, or penalties.
- Reputational damage: a breach involving trusted company accounts can weaken customer confidence and strain relationships with partners and clients.
ANY.RUN's detection and response playbook
ANY.RUN recommends three practical responses tied to its tooling. First, the Threat Intelligence Lookup can surface a characteristic N0va URL pattern and link related URLs, domains, IPs, files, sandbox sessions, and infrastructure so analysts can tell whether an indicator is isolated or part of a broader campaign. The service is presented as a way to move beyond single indicators and see recurring request structure across submissions.
Second, the Interactive Sandbox provides behavioral visibility: Tier 1 analysts can observe an attack live, from lures and redirects through network activity and follow-on behavior. ANY.RUN cites a Microsoft-themed N0va case where the sandbox produced the first malicious verdict in 24 seconds and exposed the full attack chain within the same session.
Third, Threat Intelligence Feeds can inject fresh indicators and context into SIEM, SOAR, EDR, firewalls, and other security tooling. ANY.RUN states its intelligence is built from activity observed across 16,000+ organizations and 700,000+ security professionals, and that integrating this data helps broaden detection coverage and speed alert enrichment.
What this means for technologists, procurement leaders, and end users
Technologists and security teams should treat device code phishing and token-exchange abuse as behavioral problems that require visibility beyond static indicators; ANY.RUN positions its sandbox and lookup as tools to give Tier 1 analysts evidence to resolve more cases without escalation. Procurement leaders will need to evaluate threat feed integration and sandbox capabilities when buying detection tools, since the source emphasizes pushing intelligence into SIEM, SOAR, EDR, and network controls. End users face social-engineering lures that mimic services they use every day — the campaign's reliance on legitimate authentication flows makes user-facing education necessary, because the interaction can appear credible even when it is malicious.
ANY.RUN also quantifies operational benefits for defenders who adopt this approach: reductions in Tier 1 investigation time by 20%, a 30% cut in Tier 1-to-Tier 2 escalations, and mean time to resolution shortened by 21 minutes per case. Those figures frame the firm's central argument: faster context, behavioral evidence, and fresh intelligence limit the window for an identity compromise to turn into a wider business incident.
N0va demonstrates a persistent trend in phishing: attackers are increasingly built to exploit legitimate authentication mechanisms rather than rely on obvious malware. The concrete choices for defenders are likewise practical and specific — connect intelligence into existing tools, give first-line analysts access to behavioral sandboxing, and prioritize signals that match the campaign's characteristic URL and request structures. Will organizations move quickly enough to apply those steps at scale and prevent token-capture attacks from expanding into full-blown incidents? The source leaves that as the central operational challenge.
Read the original report: https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html



