N0va Phishkit Exploits Microsoft Device-Code Authentication
A new phishing campaign, dubbed N0va Phishkit, has been targeting North America and Europe by exploiting Microsoft's device-code authentication. According to ANY.RUN, which discovered the campaign in September 2026, N0va uses lures impersonating popular services such as Microsoft Security, Teams, and OneDrive to trick victims into authorizing an attacker-initiated session.
Despite completing multifactor authentication (MFA), victims can still be convinced to authorize the wrong session, resulting in valid access and refresh tokens for attackers. This campaign highlights the importance of consistent identity monitoring and access controls, particularly for enterprises that manage Microsoft identities across multiple cloud tenants, offices, and jurisdictions.
Microsoft has documented a similar authentication weakness in a separate April 2026 campaign, where attackers directed victims through legitimate Microsoft authentication to receive valid tokens after sign-in. To mitigate this threat, security teams can audit and restrict device-code authentication, monitor suspicious activity, strengthen authentication for high-risk accounts, and apply risk-based access controls.
ANY.RUN observed N0va using token exchange and device registration in an attempt to establish Primary Refresh Token-based single sign-on access. Blocking device-code abuse and token replay is crucial to prevent malicious activity from blending in with legitimate traffic.