The N0va phishkit is targeting organizations in North America and Europe and using trusted-looking sign-in pages to steal OAuth access and refresh tokens, The Hacker News reports. The campaign has been seen against government, technology, consulting, healthcare, and other sectors.
The trick is to run the victim through a legitimate authentication flow, then capture tokens the attacker can reuse later. Those tokens act like standing keys: with them, an attacker can reopen the account, reach email and business apps, and keep access even after a password change if the sessions and grants are still live.
That makes the blast radius an identity problem, not just a bad click. Any shop that relies on SSO for cloud services inherits the same risk: token theft can preserve footholds in trusted accounts and quietly extend dwell time across the cloud estate.