Executive Summary
The N0va phishing campaign has emerged as a sophisticated threat targeting organizations across North America and Europe in 2026, focusing on government, technology, consulting, and healthcare sectors. Unlike traditional phishing attacks, N0va impersonates trusted business platforms including Microsoft Teams, SharePoint, OneDrive, DocuSign, and Google Drive, then guides victims through legitimate authentication flows to capture access and refresh tokens. Once successful, attackers abuse token-exchange mechanisms to establish SSO access across corporate resources, enabling access to email, files, and cloud applications without deploying obvious malware. The campaign's use of legitimate authentication processes and trusted brand impersonation makes detection challenging and can lead to significant financial losses, data exposure, operational disruption, and compliance violations.
This incident highlights the evolving sophistication of identity-based attacks that exploit trust in legitimate business platforms and authentication mechanisms, representing a growing trend where attackers move beyond traditional malware deployment to abuse valid business processes for initial access and persistence.
Why This Matters Now
Identity-based attacks like N0va are rapidly becoming the primary attack vector as organizations adopt cloud-first strategies, making traditional perimeter defenses insufficient against threats that abuse legitimate authentication flows and trusted business platforms.
Attack Path Analysis
N0va phishing campaign uses trusted business platform lures to guide victims through legitimate authentication flows, capturing access and refresh tokens to establish SSO access to corporate resources. Attackers leverage device code phishing and token exchange mechanisms to compromise identities across Microsoft Teams, SharePoint, OneDrive, DocuSign, and other platforms. Once authenticated, attackers can pivot to email systems, cloud applications, and sensitive data repositories. The campaign maintains persistence through token refresh mechanisms and SSO access. Data exfiltration occurs through legitimate business channels making detection challenging. Impact includes financial fraud, data exposure, operational disruption, and compliance violations across government, technology, healthcare, and consulting sectors.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
N0va delivers phishing lures impersonating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign to trick users into device code phishing flows through legitimate authentication mechanisms
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Steal Web Session Cookie
Modify Authentication Process: Hybrid Identity
Valid Accounts: Cloud Accounts
Multi-Factor Authentication Request Generation
Steal Application Access Token
Trusted Relationship
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ID.AM-2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
PCI DSS 4.0 – User Authentication Management
Control ID: 8.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
N0va phishing targets government entities across North America and Europe, compromising identity security through legitimate authentication flows and SSO access to sensitive systems.
Information Technology/IT
Technology sector faces high N0va exposure due to extensive cloud platform usage, with token-based attacks bypassing traditional security controls and enabling lateral movement.
Management Consulting
Consulting firms are specifically targeted by N0va campaigns, risking client data exposure and operational disruption through compromised business platform access and authentication flows.
Health Care / Life Sciences
Healthcare organizations face N0va phishing attacks targeting Microsoft Teams and SharePoint access, creating HIPAA compliance risks and potential exposure of patient records.
Sources
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Securityhttps://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.htmlVerified
- ANY.RUN Threat Intelligence - N0va Campaign Analysishttps://intelligence.any.run/analysis/lookupVerified
- N0va Microsoft-themed Phishing Session Analysishttps://app.any.run/tasks/26360cd2-8f2d-4de0-af60-2ec3cf60497c/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain the N0va campaign's ability to pivot across cloud applications and exfiltrate data through lateral movement restrictions and egress controls. Segmentation policies could reduce the blast radius of compromised SSO tokens across business platforms.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While the phishing attack itself may succeed, CNSF visibility would likely provide early detection of anomalous authentication patterns and token usage across cloud applications during the compromise sequence.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain the scope of SSO token privileges, limiting which cloud applications and resources the compromised identity could access even with valid authentication tokens.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement between cloud applications and services, limiting the attacker's ability to pivot freely across the connected business platform ecosystem using compromised tokens.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility could detect anomalous token refresh patterns and suspicious session behavior across different cloud platforms, potentially limiting the duration and scope of persistent access through behavioral analysis.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain data exfiltration by restricting outbound data flows and detecting unusual data access patterns, limiting the volume and types of sensitive information that could be extracted.
While financial fraud and operational disruption may still occur, the constrained lateral movement and limited data access scope would likely reduce the overall impact magnitude and accelerate recovery through contained blast radius.
Impact at a Glance
Affected Business Functions
- Identity and Access Management
- Email and Collaboration Systems
- Cloud Applications and Data Storage
- Single Sign-On (SSO) Services
Estimated downtime: 3 days
Estimated loss: $75,000
Compromised employee credentials and SSO tokens providing access to corporate email, cloud storage (OneDrive, SharePoint, Google Drive), collaboration platforms (Teams, Zoom), and document signing systems (DocuSign, Adobe Sign). Potential exposure of customer records, employee information, intellectual property, and confidential business communications across government, technology, consulting, and healthcare sectors.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with identity-based policies to limit SSO token abuse and restrict lateral movement across cloud applications and services
- • Deploy egress security controls with FQDN filtering and policy enforcement to detect and block unauthorized data exfiltration through legitimate business channels
- • Enable multicloud visibility and anomaly detection to identify suspicious authentication patterns, token exchange activities, and abnormal SSO access behaviors
- • Establish threat detection capabilities with behavioral baselining to catch device code phishing flows and legitimate-but-malicious authentication abuse
- • Integrate threat intelligence feeds into existing security tools to provide real-time IOCs and detection coverage for emerging N0va infrastructure and attack patterns



