N0va Phishkit Hijacks Legitimate Auth Flows to Steal SSO Tokens
The N0va Phishkit represents a sophisticated evolution in phishing attacks by exploiting legitimate authentication flows rather than deploying traditional malware, making it harder for conventional defenses to detect. Attackers capture OAuth access and refresh tokens, granting persistent SSO access to cloud resources and sensitive data without triggering typical endpoint security alerts. This matters because stolen tokens effectively impersonate a legitimate user session, bypassing multi-factor authentication after the initial compromise. Organizations that rely solely on perimeter defenses or signature-based detection are especially vulnerable, as the attack leverages trusted services to appear credible. The breadth of targeted sectors — government, healthcare, and technology — underscores the widespread risk to critical infrastructure.
Tactical Insight
Immediate Actions
- Enforce phishing-resistant MFA methods (e.g., FIDO2/passkeys) across all identity providers to reduce token-theft effectiveness.
- Audit and revoke suspicious OAuth token grants and active SSO sessions for all privileged and sensitive accounts immediately.
Detection Measures
- Implement continuous monitoring and anomaly detection on authentication logs to flag unusual token usage patterns, impossible travel, or unexpected SSO access.
- Deploy an Identity Threat Detection and Response (ITDR) solution to correlate authentication events and detect token replay or abuse in real time.
- Configure alerts for new OAuth application consents and refresh token issuances, especially from unfamiliar locations or devices.
Long-Term Improvements
- Establish short-lived token lifetimes and enforce Conditional Access policies that require step-up authentication for sensitive cloud resource access.
- Conduct regular phishing simulation exercises focused on credential harvesting and OAuth consent phishing to build employee resilience.
- Implement Zero Trust principles by continuously validating device posture and user context before granting access to cloud resources.