N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EU

N0va Phishkit Uses Device Code Phishing to Bypass MFA and (TL-2026-2537), also tracked as Nova Phishkit, is a high-severity phishing campaign, first published 2026-09-16. It has no confirmed attribution, affects Microsoft Microsoft Entra ID / Microsoft 365 (OAuth 2.0 Device, maps to 12 MITRE ATT&CK techniques (T1036.005, T1078.004, T1090.002), and is covered by 9 detection rules and 14 indicators of compromise.

Key facts for TL-2026-2537

Threat ID
TL-2026-2537
Also known as
Nova Phishkit
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-16
Last reviewed
2026-09-16
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, technology, consulting, health
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
14

Malware and tooling in N0va Phishkit Uses Device Code Phishing to Bypass MFA and

Malware and tooling: N0va

The N0va phishing kit impersonates trusted platforms (Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, Adobe Sign) to guide victims through the legitimate OAuth 2.0 Device Authorization Grant flow, capturing access/refresh tokens after MFA completes and exchanging them for Primary Refresh Token-based SSO access. It has hit government, technology, consulting, and healthcare organizations across North America and Europe, with confirmed payment fraud, invoice manipulation, and data exposure.

How N0va Phishkit Uses Device Code Phishing to Bypass MFA and works

N0va is a phishing kit disclosed by ANY.RUN researchers in September 2026 that abuses Microsoft's OAuth 2.0 Device Authorization Grant ("device code") flow to obtain valid access and refresh tokens without ever presenting a credential-harvesting form or a look-alike login domain. Victims are lured with pages impersonating eight widely trusted business platforms -- Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign -- and are instructed to browse to the real Microsoft device-login portal and enter an attacker-generated user code. Because the victim authenticates on Microsoft's own infrastructure and completes their normal MFA challenge, the attacker's device-code session is authorized as if it were the victim's own device, yielding usable OAuth tokens even though MFA was satisfied.

The documented attack chain runs: trusted-brand lure -> device-code phishing -> legitimate authentication -> access/refresh token capture -> token exchange and device registration -> SSO access to corporate resources. Once tokens are captured, N0va operators exchange them and abuse device-registration mechanisms to obtain Primary Refresh Token (PRT)-based single sign-on access, allowing follow-on activity to blend in with normal authenticated account use rather than triggering malware or anomalous-login detections.

N0va's infrastructure is deliberately split across compromised legitimate websites, Cloudflare Workers subdomains (*.workers.dev), and Linode Object Storage, which spreads indicators across domain reputation, hosting, and authentication telemetry so that no single detection layer sees the full chain. ANY.RUN's Threat Intelligence Lookup identified a distinguishing backend URL signature, `/api/verification/init?session=*&flow=*prompt_profile=`, that has been used to pivot onto additional related N0va infrastructure. ANY.RUN's interactive sandbox reproduced complete N0va attack chains in roughly 24 seconds, underscoring how quickly the multi-stage flow completes once a victim engages.

Observed targeting spans government, technology, consulting, and healthcare organizations in North America and the European Union. Confirmed operational impact includes payment fraud and invoice manipulation, and exposure of customer records, employee data, and intellectual property following SSO-scoped access to email, file-sharing, and collaboration platforms. No CVE or CVSS score applies -- this is an abuse of a legitimate, by-design OAuth authentication flow rather than a software vulnerability -- and no source attributes N0va to a specific named threat actor or nation-state.

N0va is the latest entrant in a device-code-phishing tradecraft wave that Microsoft first formalized publicly in February 2025 with its disclosure of Storm-2372 (active since roughly August 2024, targeting government, NGO, IT, defense, telecom, health, and energy organizations across Europe, North America, Africa, and the Middle East, assessed with moderate confidence to align with Russian interests). The Cloud Security Alliance documented the technique's continued proliferation at scale in a March 2026 research note covering more than 340 affected Microsoft 365 organizations, and open reporting references a separate April 2026 Microsoft-documented campaign using identical device-code-authentication weaknesses, as well as a distinct "BigBear 2.0" session-hijacking campaign against Microsoft 365 tenants. N0va's disclosure indicates device-code phishing has matured from a single-actor technique into repeatable, actor-agnostic phishkit tradecraft.

MITRE ATT&CK techniques used in TL-2026-2537

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location

Persistence

T1078.004 Cloud Accounts; T1098.005 Device Registration

Command and Control

T1090.002 External Proxy

Collection

T1213 Data from Information Repositories

Credential Access

T1528 Steal Application Access Token; T1556 Modify Authentication Process

lateral-movement

T1550.001 Application Access Token

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.006 Web Services; T1584.004 Server

Impact

T1657 Financial Theft

Affected products and versions in N0va Phishkit Uses Device Code Phishing to Bypass MFA and

  • Microsoft — Microsoft Entra ID / Microsoft 365 (OAuth 2.0 Device Authorization Grant / "device code" flow)
    Vulnerable versions: Tenants with the device code authentication flow enabled by default and no restricting Conditional Access policy
    Fixed in: Tenants with Conditional Access policies that block or restrict the device-code flow to trusted apps/locations
  • Multiple (impersonated only, not themselves vulnerable) — Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, Adobe Sign

Remediation for N0va Phishkit Uses Device Code Phishing to Bypass MFA and

Immediate actions

  • Restrict or disable the OAuth 2.0 Device Authorization Grant (device code flow) tenant-wide via Microsoft Entra Conditional Access unless a specific line-of-business need requires it
  • Revoke refresh and access tokens and force re-authentication for any account that completed a device-code sign-in from an unfamiliar application, client ID, geography, or ASN
  • Hunt Entra ID / Microsoft 365 sign-in logs for the device-code grant type combined with unfamiliar client IDs or immediately-following device-registration events
  • Block or alert on the identified N0va URL signature `/api/verification/init?session=*&flow=*prompt_profile=` and on referrers from Cloudflare Workers (*.workers.dev) and Linode Object Storage at the web proxy / SWG

Workarounds

  • Where the device code flow cannot be disabled outright, restrict it to specific named applications and trusted network locations using Conditional Access named locations and application-based Conditional Access

Longer-term hardening

  • Move high-value users to phishing-resistant MFA (FIDO2/WebAuthn, certificate-based authentication) that cannot be satisfied by simply approving a displayed code
  • Require compliant/managed devices via Conditional Access for any flow that still permits device-code or legacy authentication
  • Add SSL/TLS decryption and identity-aware web proxy inspection so device-code phishing pages and follow-on API calls are visible to network security tooling
  • Correlate identity-provider sign-in and token-issuance telemetry with email, endpoint, and network detections in SIEM/SOAR rather than relying on any single signal

Timeline of N0va Phishkit Uses Device Code Phishing to Bypass MFA and

  • Microsoft Threat Intelligence later reports that Storm-2372 began conducting device-code phishing campaigns around this time, targeting government, NGO, IT, defense, telecom, health, and energy organizations across Europe, North America, Africa, and the Middle East -- establishing the device-code-authentication-abuse tradecraft that N0va would later reuse. (Related precedent activity, not N0va itself.)
  • Microsoft Security Blog publishes "Storm-2372 conducts device code phishing campaign," publicly formalizing detection and defense guidance for the OAuth device-code-phishing technique that N0va later leverages. (Background reference, not N0va-specific.)
  • The Cloud Security Alliance publishes a research note documenting device-code phishing affecting more than 340 Microsoft 365 organizations, showing the technique had proliferated well beyond a single actor ahead of N0va's disclosure. (Background reference, not N0va-specific.)
  • Open reporting references a separate Microsoft-documented campaign employing identical device-code-authentication weaknesses, indicating continued active abuse of the technique by multiple operators. (Related campaign, not N0va itself.)
  • ANY.RUN researchers disclose the N0va phishkit, identifying its brand-impersonation lures, its device-code-phishing attack chain, its split infrastructure across compromised sites, Cloudflare Workers, and Linode Object Storage, and a distinguishing backend URL signature used to pivot onto related infrastructure via Threat Intelligence Lookup.
  • eSecurityPlanet, Cybersecurity News, and First Hackers News publish follow-on analyses of N0va, adding detection guidance covering interactive sandboxing, cross-signal correlation across domain/IP/hosting/authentication activity, and SIEM/SOAR/EDR integration.
  • The Hacker News publishes coverage of N0va based on ANY.RUN's findings, detailing targeting of government, technology, consulting, and healthcare organizations in North America and the EU and confirming operational impact including payment fraud, invoice manipulation, and exposure of customer records, employee data, and intellectual property.

Sources cited for N0va Phishkit Uses Device Code Phishing to Bypass MFA and

More in phishing

Detection coverage for TL-2026-2537

As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2537 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats