Phishing attacks are changing. Attackers are no longer focused only on stealing usernames and passwords. They are increasingly targeting authentication sessions, access tokens, and trusted business services.
A recent campaign involving the N0va phishkit shows how this approach is evolving.
Researchers found N0va being used against organizations in North America and Europe, with targets including government, technology, consulting, and healthcare.
What makes this campaign concerning is the way it blends into normal business activity. Instead of relying on an obviously fake login page, N0va can use familiar brands and legitimate authentication processes to make the attack look genuine.
The Attack Starts With Something Familiar
Employees regularly use services such as Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign.
N0va takes advantage of that familiarity.
Attackers create phishing pages that closely resemble these trusted services and use them to guide victims through an authentication process.
In one investigation, researchers observed a Microsoft-themed N0va page using a device-code authentication flow.
To the user, the process can appear similar to a normal Microsoft verification step.
That is where the risk increases.
The attacker is not simply trying to collect a password. The campaign can potentially obtain authentication tokens and use device-registration mechanisms to establish access to corporate resources.
From Phishing to Account Access
The important part of the N0va campaign is what happens after the victim interacts with the phishing page.
The attack can follow a chain similar to:
Trusted service → Phishing lure → Device-code authentication → Token theft → Token abuse → Corporate resource access
This changes the way SOC teams need to investigate phishing incidents.
A suspicious email may be the starting point, but it may not contain enough information to understand what happened afterward.
The real investigation may involve identity logs, browser activity, authentication events, endpoint data, domains, IP addresses, and cloud activity.
Why This Is Difficult for SOC Teams
Traditional phishing detection often looks for obvious warning signs:
- Suspicious domains
- Fake login pages
- Malicious attachments
- Unusual URLs
- Credential harvesting
N0va demonstrates why that approach is no longer enough.
When attackers use legitimate authentication services and familiar brands, some activity may look completely normal.
This creates several challenges for SOC teams.
The first is visibility. The evidence may be spread across multiple security platforms.
The second is authentication abuse. A successful login does not always mean the activity is legitimate.
The third is investigation time. Analysts may need to connect several seemingly unrelated events before they can confirm an attack.
The fourth is persistence. If attackers obtain usable tokens, removing the original phishing page may not immediately remove their access.
What SOC Leaders Should Take From N0va
N0va is less about one phishing kit and more about a broader change in attacker behavior.
Identity has become a major part of the attack surface.
For SOC leaders, this means phishing detection should not stop at the email gateway. Teams need to understand what happens when a user clicks, authenticates, receives a token, or registers a device.
1. Investigate Beyond the URL
A suspicious URL should be the beginning of an investigation, not the end.
Security analysts should be able to safely open suspicious pages, follow redirects, observe authentication behavior, and determine what the website is attempting to do.
Interactive sandboxing can help Tier 1 analysts perform this analysis without exposing the corporate environment.
ANY.RUN reports that its platform can reduce Tier 1 workload by up to 20% and Tier 1-to-Tier 2 escalations by up to 30%.
2. Connect the Indicators
One domain rarely tells the entire story.
An investigation may start with a phishing URL and then lead to:
Domain → IP → Hosting infrastructure → Authentication activity → Targeted organization → Related attacks
Threat intelligence can help analysts make these connections faster.
With broader context, SOC teams can determine whether an indicator is an isolated event or part of a larger campaign.
3. Turn Intelligence Into Detection
Finding malicious infrastructure is useful only if the organization can act on it.
Indicators identified during an investigation should be pushed into the wider security environment where appropriate.
Threat intelligence feeds can provide updated malicious domains, IP addresses, and URLs that can be used by SIEM, SOAR, EDR, firewalls, and other security controls.
This allows one investigation to improve protection across the organization instead of remaining inside a single analyst’s case.
The Bigger Identity Security Problem
N0va highlights an important shift in modern phishing.
The objective is no longer always to steal credentials. The objective can be to obtain trusted access.
That distinction matters.
An attacker using a stolen password may trigger traditional security controls. An attacker abusing legitimate authentication and valid tokens can be much harder to distinguish from a real user.
For CISOs and SOC leaders, identity signals therefore need to become part of the broader detection strategy.
Email security, identity protection, endpoint monitoring, threat intelligence, and network visibility should work together rather than operate as separate layers.
Building a More Resilient SOC
The N0va campaign reinforces a simple lesson:
A phishing alert is only the first piece of the investigation.
Modern SOCs need the ability to understand the complete attack path—from the initial lure to authentication and potential access to corporate resources.
Faster analysis, connected threat intelligence, and broader detection coverage can help security teams identify identity-based attacks earlier and reduce the time needed to investigate them.
ANY.RUN reports improvements of up to 3× in SOC efficiency, up to 21 minutes less MTTR per case, and up to 36% improvement in detection coverage.
As phishing becomes increasingly tied to identity attacks, organizations that can connect these signals will be better positioned to detect compromise before it becomes a larger security incident.