N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EU
N0va Phishkit Uses Device Code Phishing to Bypass MFA and (TL-2026-2537), also tracked as Nova Phishkit, is a high-severity phishing campaign, first published 2026-09-16. It has no confirmed attribution, affects Microsoft Microsoft Entra ID / Microsoft 365 (OAuth 2.0 Device, maps to 12 MITRE ATT&CK techniques (T1036.005, T1078.004, T1090.002), and is covered by 9 detection rules and 14 indicators of compromise.
Key facts for TL-2026-2537
- Threat ID
- TL-2026-2537
- Also known as
- Nova Phishkit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-16
- Last reviewed
- 2026-09-16
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, technology, consulting, health
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in N0va Phishkit Uses Device Code Phishing to Bypass MFA and
Malware and tooling: N0va
The N0va phishing kit impersonates trusted platforms (Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, Adobe Sign) to guide victims through the legitimate OAuth 2.0 Device Authorization Grant flow, capturing access/refresh tokens after MFA completes and exchanging them for Primary Refresh Token-based SSO access. It has hit government, technology, consulting, and healthcare organizations across North America and Europe, with confirmed payment fraud, invoice manipulation, and data exposure.
How N0va Phishkit Uses Device Code Phishing to Bypass MFA and works
N0va is a phishing kit disclosed by ANY.RUN researchers in September 2026 that abuses Microsoft's OAuth 2.0 Device Authorization Grant ("device code") flow to obtain valid access and refresh tokens without ever presenting a credential-harvesting form or a look-alike login domain. Victims are lured with pages impersonating eight widely trusted business platforms -- Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign -- and are instructed to browse to the real Microsoft device-login portal and enter an attacker-generated user code. Because the victim authenticates on Microsoft's own infrastructure and completes their normal MFA challenge, the attacker's device-code session is authorized as if it were the victim's own device, yielding usable OAuth tokens even though MFA was satisfied.
The documented attack chain runs: trusted-brand lure -> device-code phishing -> legitimate authentication -> access/refresh token capture -> token exchange and device registration -> SSO access to corporate resources. Once tokens are captured, N0va operators exchange them and abuse device-registration mechanisms to obtain Primary Refresh Token (PRT)-based single sign-on access, allowing follow-on activity to blend in with normal authenticated account use rather than triggering malware or anomalous-login detections.
N0va's infrastructure is deliberately split across compromised legitimate websites, Cloudflare Workers subdomains (*.workers.dev), and Linode Object Storage, which spreads indicators across domain reputation, hosting, and authentication telemetry so that no single detection layer sees the full chain. ANY.RUN's Threat Intelligence Lookup identified a distinguishing backend URL signature, `/api/verification/init?session=*&flow=*prompt_profile=`, that has been used to pivot onto additional related N0va infrastructure. ANY.RUN's interactive sandbox reproduced complete N0va attack chains in roughly 24 seconds, underscoring how quickly the multi-stage flow completes once a victim engages.
Observed targeting spans government, technology, consulting, and healthcare organizations in North America and the European Union. Confirmed operational impact includes payment fraud and invoice manipulation, and exposure of customer records, employee data, and intellectual property following SSO-scoped access to email, file-sharing, and collaboration platforms. No CVE or CVSS score applies -- this is an abuse of a legitimate, by-design OAuth authentication flow rather than a software vulnerability -- and no source attributes N0va to a specific named threat actor or nation-state.
N0va is the latest entrant in a device-code-phishing tradecraft wave that Microsoft first formalized publicly in February 2025 with its disclosure of Storm-2372 (active since roughly August 2024, targeting government, NGO, IT, defense, telecom, health, and energy organizations across Europe, North America, Africa, and the Middle East, assessed with moderate confidence to align with Russian interests). The Cloud Security Alliance documented the technique's continued proliferation at scale in a March 2026 research note covering more than 340 affected Microsoft 365 organizations, and open reporting references a separate April 2026 Microsoft-documented campaign using identical device-code-authentication weaknesses, as well as a distinct "BigBear 2.0" session-hijacking campaign against Microsoft 365 tenants. N0va's disclosure indicates device-code phishing has matured from a single-actor technique into repeatable, actor-agnostic phishkit tradecraft.
MITRE ATT&CK techniques used in TL-2026-2537
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Persistence
T1078.004 Cloud Accounts; T1098.005 Device Registration
Command and Control
Collection
T1213 Data from Information Repositories
Credential Access
T1528 Steal Application Access Token; T1556 Modify Authentication Process
lateral-movement
T1550.001 Application Access Token
Initial Access
Resource Development
T1583.006 Web Services; T1584.004 Server
Impact
Affected products and versions in N0va Phishkit Uses Device Code Phishing to Bypass MFA and
- Microsoft — Microsoft Entra ID / Microsoft 365 (OAuth 2.0 Device Authorization Grant / "device code" flow)
Vulnerable versions: Tenants with the device code authentication flow enabled by default and no restricting Conditional Access policy
Fixed in: Tenants with Conditional Access policies that block or restrict the device-code flow to trusted apps/locations - Multiple (impersonated only, not themselves vulnerable) — Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, Adobe Sign
Remediation for N0va Phishkit Uses Device Code Phishing to Bypass MFA and
Immediate actions
- Restrict or disable the OAuth 2.0 Device Authorization Grant (device code flow) tenant-wide via Microsoft Entra Conditional Access unless a specific line-of-business need requires it
- Revoke refresh and access tokens and force re-authentication for any account that completed a device-code sign-in from an unfamiliar application, client ID, geography, or ASN
- Hunt Entra ID / Microsoft 365 sign-in logs for the device-code grant type combined with unfamiliar client IDs or immediately-following device-registration events
- Block or alert on the identified N0va URL signature `/api/verification/init?session=*&flow=*prompt_profile=` and on referrers from Cloudflare Workers (*.workers.dev) and Linode Object Storage at the web proxy / SWG
Workarounds
- Where the device code flow cannot be disabled outright, restrict it to specific named applications and trusted network locations using Conditional Access named locations and application-based Conditional Access
Longer-term hardening
- Move high-value users to phishing-resistant MFA (FIDO2/WebAuthn, certificate-based authentication) that cannot be satisfied by simply approving a displayed code
- Require compliant/managed devices via Conditional Access for any flow that still permits device-code or legacy authentication
- Add SSL/TLS decryption and identity-aware web proxy inspection so device-code phishing pages and follow-on API calls are visible to network security tooling
- Correlate identity-provider sign-in and token-issuance telemetry with email, endpoint, and network detections in SIEM/SOAR rather than relying on any single signal
Timeline of N0va Phishkit Uses Device Code Phishing to Bypass MFA and
- Microsoft Threat Intelligence later reports that Storm-2372 began conducting device-code phishing campaigns around this time, targeting government, NGO, IT, defense, telecom, health, and energy organizations across Europe, North America, Africa, and the Middle East -- establishing the device-code-authentication-abuse tradecraft that N0va would later reuse. (Related precedent activity, not N0va itself.)
- Microsoft Security Blog publishes "Storm-2372 conducts device code phishing campaign," publicly formalizing detection and defense guidance for the OAuth device-code-phishing technique that N0va later leverages. (Background reference, not N0va-specific.)
- The Cloud Security Alliance publishes a research note documenting device-code phishing affecting more than 340 Microsoft 365 organizations, showing the technique had proliferated well beyond a single actor ahead of N0va's disclosure. (Background reference, not N0va-specific.)
- Open reporting references a separate Microsoft-documented campaign employing identical device-code-authentication weaknesses, indicating continued active abuse of the technique by multiple operators. (Related campaign, not N0va itself.)
- ANY.RUN researchers disclose the N0va phishkit, identifying its brand-impersonation lures, its device-code-phishing attack chain, its split infrastructure across compromised sites, Cloudflare Workers, and Linode Object Storage, and a distinguishing backend URL signature used to pivot onto related infrastructure via Threat Intelligence Lookup.
- eSecurityPlanet, Cybersecurity News, and First Hackers News publish follow-on analyses of N0va, adding detection guidance covering interactive sandboxing, cross-signal correlation across domain/IP/hosting/authentication activity, and SIEM/SOAR/EDR integration.
- The Hacker News publishes coverage of N0va based on ANY.RUN's findings, detailing targeting of government, technology, consulting, and healthcare organizations in North America and the EU and confirming operational impact including payment fraud, invoice manipulation, and exposure of customer records, employee data, and intellectual property.
Sources cited for N0va Phishkit Uses Device Code Phishing to Bypass MFA and
- N0va Phishkit Targets US and EU
- N0va Phishkit Targets North America and Europe Through Microsoft Logins
- New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs
- New N0va Phishkit Campaign Puts Enterprise Identities At Risk
- ANY.RUN: We uncovered #N0va, a new phishkit targeting organizations in North America and Europe
- Storm-2372 conducts device code phishing campaign
- OAuth Device Code Phishing Hits 340+ Microsoft 365 Organizations
More in phishing
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via Google Cloud Storage / Vercel / Google Sites Redirect Chain
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund Scams
Detection coverage for TL-2026-2537
As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2537 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.