N0va Device-Code Phish Steals Microsoft Sessions

eSecurity Planet · High sophistication
Last updated September 11, 2026

Researchers reported a real phishing operation (“N0va” phishkit) that tricks people into signing into Microsoft through a legitimate Microsoft page, but for an attacker-started session. Victims can complete MFA and still grant the attacker access and refresh tokens, letting the attacker operate as the user and potentially blend in with normal sign-ins.

Key findings

  • N0va abuses Microsoft device-code authentication so a user can complete MFA on a legitimate Microsoft sign-in page while authorizing an attacker-initiated session.
  • ANY.RUN observed targeting across North America and Europe, including government, technology, consulting, and healthcare organizations.
  • Lures impersonated common enterprise services (e.g., Microsoft Security/Teams/SharePoint/OneDrive, DocuSign, Google Drive, Dropbox, Zoom, Adobe Sign).
  • Infrastructure was hosted via compromised legitimate websites and services like Cloudflare Workers and Linode Object Storage.
  • Microsoft guidance emphasizes restricting or blocking device-code flow and monitoring suspicious authentication and token activity.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT / IAM teams, Security Operations (SOC), Helpdesk / Service Desk, Privileged administrators.
  • Affected industries: Government, Technology, Consulting / Professional Services, Healthcare.
  • Attack channels: email, website.
  • Impersonated: Microsoft Security (or Microsoft 365 service such as Teams/SharePoint/OneDrive), Microsoft Security.

Awareness takeaways

  • Teach users: a real Microsoft login page is not proof the request is safe, only approve sign-ins you personally initiated.
  • Train staff to treat unexpected device-code sign-ins and unfamiliar app consent prompts as suspicious and to report them immediately.
  • Reinforce that MFA success is not the end of the story, security teams must monitor token activity and post-login behavior.
  • For incident response drills, include steps beyond password reset: revoke refresh tokens, force reauthentication, and review account/device changes.

Red flags to watch for

  • You are asked to approve a sign-in/session you did not initiate.
  • The message uses a generic “shared document/signature” urgency without context.
  • Unexpected device-code style sign-in prompts or unusual authentication activity during the process.
  • Security alert arrives unexpectedly and pressures immediate action.
  • The sign-in is legitimate-looking, but the user didn’t start the session/request.
  • Post-login behavior looks “normal” because tokens are valid (harder to spot).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You open an email: “Action required: Sign in to view the shared file.” You click, and a real Microsoft login page pops up. Here’s the trick: a N0va device-code phish started this session, not you. You can pass MFA on a genuine Microsoft page and still hand over access and refresh tokens. ANY.RUN saw this used against Microsoft Security, Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, Adobe Sign, always the same move: “Verify sign-in,” but you never started it. If a Microsoft sign-in or device-code prompt appears for a session you didn’t start, stop and report it to security immediately, MFA or not.

Similar attacks

Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Kali365 Tricks Staff Into Approving Real Microsoft Logins

Kali365 Tricks Staff Into Approving Real Microsoft Logins

Kali365 is a phishing kit that abuses Microsoft’s real “device code” sign-in flow to trick employees into approving attacker-controlled login codes. Once a victim completes authentication on Microsoft’s legitimate page, attackers can receive access and refresh tokens that may grant ongoing access…

August 5, 2026
Russian Hackers Used AI to Evolve Phishing & Malware

Russian Hackers Used AI to Evolve Phishing & Malware

Anthropic says it disrupted a Russian state-linked campaign that used Claude to continuously rebuild malware when security tools detected it. The group (GTG-20006, linked to Midnight Blizzard/APT29) ran phishing and other human-targeted schemes, including device-code token theft against Microsoft…

September 11, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Kratos PhaaS Takedown: Fake Microsoft Logins

Kratos PhaaS Takedown: Fake Microsoft Logins

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account logins. The kit provided convincing Microsoft-themed fake login pages designed to steal passwords and session cookies, which could help…

July 21, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026