Skip to content

Security1 publisher2 min readPublished

N0va captures refresh tokens from sign-ins the identity provider itself approved

ANY.RUN says the kit lures staff with Teams, DocuSign and Dropbox pages, walks them through a genuine device code sign-in, and then takes the access and refresh tokens to register a device of its own.

The Watch · Security desk

Illustration accompanying N0va captures refresh tokens from sign-ins the identity provider itself approved

What happened

  • ANY.RUN says N0va phishing activity has hit government, technology, consulting and healthcare organizations in North America and Europe with lures that impersonate trusted services.
  • The campaign uses more than a cloned login page: it guides the victim through the provider's genuine authentication flow, which ANY.RUN says makes the interaction appear more credible.
  • Once the user finishes authenticating, the kit captures access and refresh tokens and abuses token exchange or device registration to stand up SSO access to corporate resources.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Whoever holds the refresh token can reach email, files and cloud applications tied to the compromised identity, and never has to run code on a company laptop.
  • constraint The chain as published leaves authentication, token exchange and device registration records, and hardly anything more. A team hunting this in endpoint data is looking at the wrong source.
  • cost Sessions get revoked, access gets reset and services get restricted while investigators work through the affected systems.
  • decision Each N0va URL forces a campaign-or-one-off call, and ANY.RUN's argument is that handling them as separate phishing events is what lets the kit keep working.

Three of the six stages ANY.RUN lists happen after the victim's last click: the token capture, the token exchange or device registration, and the SSO access to corporate resources [15][8]. All three are identity-plane actions [6]. The write-up's own summary is that a successful run gives "access to valid accounts without relying on obvious malware activity" [2].

The reason the interaction holds up is that the victim authenticates on the real flow, which ANY.RUN says makes it appear more credible than a cloned page [5]. The provider issues working tokens because the sign-in was working, and the account they belong to stays valid [1].

Eight platforms are named in the lure set: Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom and Adobe Sign [14][4]. The sector list is government, technology, consulting, healthcare "and other sectors" in North America and Europe [3]. That list is wide enough that a reader cannot tell from it whether they are in scope.

The account is ANY.RUN's, carried on thehackernews.com, and it recommends the company's Threat Intelligence Lookup for deciding whether an N0va indicator is isolated or part of the wider campaign [13][16]. It points analysts at a characteristic N0va URL pattern but keeps the pattern itself out of the write-up, along with any dates or victim count [12].

The kit abuses authentication flows that work as designed [1]. There is no CVE and no patch. What a defender can look for is bounded by what that chain leaves behind, and by ANY.RUN's account that is a completed authentication, a token exchange and a device registration [8]. The cost side is in the same write-up: containment forces teams to revoke sessions, reset access, investigate affected systems and restrict services while the incident is open [10], and exposure of regulated data can trigger reporting requirements, investigations, contractual issues or penalties [11].

ANY.RUN says impact depends on the compromised user's rights, with email, files, cloud applications and other connected corporate resources available through the stolen identity [9][7]. A finance approver and a contractor with read access to one SharePoint site produce different incidents from the same phishing email.

What to watch

  • Whether ANY.RUN or another vendor publishes the N0va URL pattern and infrastructure indicators so defenders can hunt without the product.
  • Whether any dated incident or named victim organization is tied to N0va, which would put a size on a campaign whose scale is not yet public.
  • Whether identity providers move to restrict device code sign-in by default in response to kits built on that flow.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories