What Happened
Researchers at ANY.RUN detailed a phishing kit named N0va, active against organizations across North America and Europe in government, technology, consulting, healthcare, and other sectors. Rather than relying on a standard fake login page, N0va impersonates trusted business platforms, including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign, and walks victims through the legitimate device-code authentication flow those services already use. Once a victim completes the real authentication step, N0va captures the resulting access and refresh tokens and abuses token-exchange or device-registration mechanisms to establish single sign-on access, all without deploying malware on the endpoint. Researchers observed attack infrastructure spread across compromised legitimate websites, Cloudflare Workers, and Linode Object Storage. Read the original report from The Hacker News.
Why This Matters for Canadian Organizations
Microsoft 365 dominates Canadian enterprise, government, and healthcare environments, and device-code authentication remains enabled by default in many Microsoft 365 tenants because legacy devices and command-line tools depend on it, giving N0va a wide surface. Because the kit captures tokens after a genuine multi-factor authentication step rather than trying to defeat MFA directly, standard push notifications and one-time codes do nothing to stop it, an important distinction for Canadian security teams treating MFA enrollment alone as sufficient protection under OSFI B-13 and federal identity guidance. The sectors N0va already targets, government, healthcare, and consulting, overlap heavily with Canadian public-sector and regulated-industry deployments of the same platforms the kit impersonates.
What to Do
Security teams should restrict or disable device-code authentication in Microsoft Entra ID conditional access policies wherever legacy device support allows it, and flag device-code sign-in events for review rather than treating them as routine. Organizations should move toward phishing-resistant authentication methods such as FIDO2 security keys for high-value accounts, and train staff to treat any prompt asking them to enter a code on a second device as a signal to verify the request through a separate channel first.






