- How N0va Turns Trusted Services into an Attack Path
- How the N0va Attack Works
- What This Means for SOC Leaders
- 3 Ways CISOs Can Reduce Identity Risk Caused by N0va
- 1. Give Tier 1 Analysts More Context Before They Escalate
- 2. Give Your SOC the Context to Connect Related Activity
- 3. Turn Threat Findings into Broader Detection Coverage
- Strengthen Your SOC Against Identity-Based Threats
Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the EU, including government, technology, consulting, and healthcare.
What makes N0va especially relevant for SOC leaders is how it spreads the attack across different layers.
Legitimate authentication, trusted brand lures, compromised websites, and cloud infrastructure can leave security teams with only part of the picture, making it easier to miss account compromise and harder to investigate the full chain.
How N0va Turns Trusted Services into an Attack Path
N0va relies on lures that imitate tools employees use every day, including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign.
In one ANY.RUN sandbox session, researchers observed a Microsoft-themed lure that guided the victim through a device code authentication flow.
The page closely mimicked a legitimate Microsoft verification experience, making the interaction look familiar while directing the user into the attacker’s flow. Check sandbox session with Microsoft-themed N0va lure

A successful N0va attempt can give attackers more than a password. By obtaining access and refresh tokens and abusing device-registration mechanisms, they can establish SSO access to corporate resources and potentially remain active even after the initial phishing interaction is over.
Give your SOC the context to contain identity threats faster, cut response time, and reduce the cost and disruption of compromised access. Cut MTTR by 21 Min/Case
How the N0va Attack Works
The attack starts with a phishing lure that imitates a trusted business service and directs the victim into a device code authentication flow.
Once the user completes the legitimate authentication step, N0va can obtain access and refresh tokens, then abuse token-exchange and device-registration mechanisms to establish SSO access.

In short, the chain looks like this:
Trusted-brand lure → Device code phishing → Legitimate authentication → Access and refresh token capture → Token exchange / device registration → SSO access to corporate resources
What This Means for SOC Leaders
N0va turns a familiar business workflow into an identity risk. Because the campaign uses trusted brands and legitimate authentication flows, a successful phishing attempt can lead to more than a stolen password.
For CISOs and SOC leaders, the main concerns are:
- Account takeover: stolen access and refresh tokens can give attackers continued access to corporate accounts.
- MFA blind spots: legitimate Microsoft authentication can make the activity look less suspicious than a traditional fake login page.
- Limited visibility: phishing pages, authentication, and backend infrastructure may appear across different tools, making the full chain harder to connect.
- Longer attacker access: token-based access can remain valid even after the original phishing page is taken down.
- Higher investigation effort: analysts may need to correlate email, identity, browser, and network activity to understand whether an account was actually compromised.
3 Ways CISOs Can Reduce Identity Risk Caused by N0va
N0va highlights three areas where SOC leaders can strengthen their defenses: faster validation at Tier 1, better threat context across investigations, and broader detection coverage across the security stack.
Addressing these gaps can help teams reduce unnecessary escalations, understand identity threats faster, and respond with more confidence.
1. Give Tier 1 Analysts More Context Before They Escalate
Identity-focused phishing can be difficult to assess from a URL, email, or login event alone. When frontline analysts lack enough context, suspicious cases are more likely to be escalated simply because the risk cannot be ruled out quickly.
ANY.RUN’s interactive sandbox gives Tier 1 analysts a safe environment to reproduce phishing behavior, follow redirects, inspect browser activity, and see what happens after user interaction.
This helps them understand whether a suspicious event is an isolated lure or part of a wider identity attack.

For SOC leaders, that can translate into measurable capacity gains. ANY.RUN reports up to a 20% decrease in Tier 1 workload and a 30% reduction in Tier 1-to-Tier 2 escalations, helping senior analysts spend more time on cases that genuinely require deeper investigation.
2. Give Your SOC the Context to Connect Related Activity
N0va shows why a single indicator rarely tells the whole story. A phishing URL, cloud-hosted landing page, backend server, or authentication event may look low-risk in isolation, while the wider campaign only becomes clear once those signals are connected.
With Threat Intelligence Lookup, SOC teams can pivot from one domain, IP, URL, or other indicator to related infrastructure, sandbox activity, and threat context.
In the N0va investigation, that broader view helped researchers understand not only how the infrastructure was connected, but also where the activity was appearing and which industries were being targeted, including government, technology, consulting, and healthcare organizations across North America and Europe.
TI query: url:”/api/verification/init?session=*&flow=*prompt_profile=”

For CISOs, this means giving analysts the context to move beyond individual alerts and understand the scope of a campaign faster.
Instead of manually piecing together disconnected indicators, the SOC can see relationships, affected regions, and targeted sectors in one investigation and make better decisions about prioritization and response.
3. Turn Threat Findings into Broader Detection Coverage
Once your SOC identifies N0va-related infrastructure, the next priority is making sure the rest of the environment can recognize similar activity before another user reaches it.
ANY.RUN Threat Intelligence Feeds deliver fresh malicious IPs, domains, and URLs into the security tools your team already uses, helping extend detection beyond a single investigation.
The intelligence is enriched by threat activity observed across a global community of 16,000+ organizations and 700,000+ security professionals, giving SOC teams broader visibility into infrastructure that is actively being used in real attacks.

For CISOs, the value is in turning what one analyst discovers into protection for the wider organization.
Instead of leaving useful indicators inside an individual case, the SOC can push them into SIEM, SOAR, EDR, firewalls, and other detection systems, helping teams spot related activity earlier and reduce the chance that the same infrastructure reaches another employee.
Strengthen Your SOC Against Identity-Based Threats
N0va shows how phishing can quickly turn into an identity-security problem when attackers combine trusted services, legitimate authentication, and distributed infrastructure.
For CISOs, the priority is giving the SOC enough visibility and context to detect these attacks earlier and respond before access spreads.
With ANY.RUN, security teams can achieve up to 3× higher SOC efficiency, reduce MTTR by up to 21 minutes per case, and improve detection coverage by up to 36%.
That gives teams more capacity to investigate identity threats without adding the same level of analyst overhead.
Cut investigation time with behavior-based analysis and give your SOC the context to stop identity threats sooner. Improve SOC Response

