N0va Phishkit Uses Trusted Apps to Steal SSO Access

The Hacker News · High sophistication
Last updated September 16, 2026

A phishing kit dubbed N0va is targeting organizations in North America and Europe by impersonating familiar business services (like Microsoft Teams/SharePoint and DocuSign) and pushing victims through legitimate sign-in flows. By capturing authentication tokens rather than dropping obvious malware, attackers can gain access to corporate email, files, and cloud applications tied to the victim’s account.

Key findings

  • N0va targets organizations in North America and Europe across multiple sectors (including government, technology, consulting, and healthcare).
  • The lures impersonate widely used business platforms (Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, Adobe Sign).
  • The workflow abuses legitimate authentication, enabling token capture and subsequent SSO access rather than relying on obvious malware.
  • A characteristic URL/request pattern was highlighted: "/api/verification/init?session=*&flow=*prompt_profile=".

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, IT / Helpdesk, Cloud application users (Microsoft 365 / SSO users).
  • Affected industries: Government, Technology, Consulting / Professional Services, Healthcare, Other sectors in North America and Europe.
  • Attack channels: email, website.
  • Impersonated: Microsoft Teams / SharePoint / OneDrive (trusted collaboration services), A trusted cloud business platform (Microsoft-themed lure referenced).

Awareness takeaways

  • Treat unexpected “document shared” and “sign-in required” messages as high risk, even when the brand (Teams/SharePoint/DocuSign) looks correct.
  • Train employees to be cautious of authentication prompts initiated from email links, because attackers may abuse legitimate sign-in flows to capture access.
  • Emphasize rapid reporting: one stolen account can cascade into wider business impact if it goes unnoticed.

Red flags to watch for

  • Unexpected collaboration/document notification you weren’t expecting
  • Sign-in flow or redirect behavior feels unusual even if the branding looks familiar
  • Pressure to authenticate immediately to view a file or message
  • Authentication prompts triggered by an email/link rather than your normal app workflow
  • A verification step that doesn’t match typical company login processes
  • Links leading to unfamiliar domains or unusual URL structures
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get this email: “A file was shared with you in Microsoft Teams, sign in to view.” Looks totally normal, right? Behind that button might be N0va, a phishing kit that abuses real Microsoft and Google sign-in screens. You click, you see the usual company SSO, you log in, and N0va quietly grabs your access tokens. Here’s the trap: the login is real, the brand is real, Teams, SharePoint, DocuSign, Google Drive, Dropbox, Zoom, but the path there is wrong. It started from an email or website you weren’t expecting, and the redirects feel off. If a “document shared” or “sign-in required” email feels even slightly off, don’t log in from that link, open the app yourself and check there, then report the email to security.

Similar attacks

N0va Device-Code Phish Steals Microsoft Sessions

N0va Device-Code Phish Steals Microsoft Sessions

Researchers reported a real phishing operation (“N0va” phishkit) that tricks people into signing into Microsoft through a legitimate Microsoft page, but for an attacker-started session. Victims can complete MFA and still grant the attacker access and refresh tokens, letting the attacker operate as…

September 11, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
One-Click Copilot Link Triggers Data Exfil

One-Click Copilot Link Triggers Data Exfil

Researchers showed how an attacker could trick Microsoft Copilot into running a malicious prompt automatically just by getting a user to click a specially crafted link. The prompt can then make Copilot search connected accounts (like email and cloud storage) and send information to an external…

August 18, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026