Threat Intelligence

New Phishing Kit 'N0va' Hijacks Logins by Abusing Real Authentication Systems

The Hacker News · 16 Sept 2026
Key Takeaway Train staff to verify login prompts carefully and enable multi-factor authentication with monitoring for unusual sign-in activity, since a single stolen login can expose your whole business.

A new phishing toolkit known as N0va is being used to target organisations across North America and Europe, including government, technology, consulting and healthcare sectors. Rather than relying on obvious malware, N0va impersonates trusted business platforms such as Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom and Adobe Sign, and abuses legitimate authentication processes to steal account access.

Once a victim completes what looks like a normal login, N0va can capture access and refresh tokens and misuse token exchange or device registration features to gain ongoing single sign on access. This means attackers can potentially reach email, files, cloud applications, and other connected business systems, all without needing to install malware on the device.

Because the phishing pages closely mimic real login flows, these attacks can be harder for staff to spot than traditional fake login pages. Security researchers note that a single compromised identity can lead to much wider business impact depending on what systems and data that account can access.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.