Cybersecurity researchers have unveiled a new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies, which is designed to redirect Microsoft 365 sign-ins while capturing authenticated sessions. This toolkit, characterized as a subscription-based phishing platform costing $320 per month, has reportedly targeted hundreds of organizations across various sectors in the U.S., U.K., Canada, Germany, Israel, and the U.A.E.
According to a report shared with The Hacker News, campaigns utilizing NovaCookies have employed genuine Docusign envelopes to carry counterfeit document-share lures. Some clicks are routed through legitimate Microsoft or Google sign-in endpoints, making the phishing attempts appear trustworthy until users reach the attacker-controlled infrastructure.
NovaCookies operates by relaying Microsoft 365 authentication through its infrastructure, allowing it to harvest session data after victims enter their passwords and multi-factor authentication (MFA) codes. Evidence suggests that the toolkit is advertised via Telegram, which is also used for managing customer profiles and support.
Notably, NovaCookies is considered a variant of the Sneaky 2FA phishing kit, with enhancements that include dedicated flows for other identity providers like Okta and Entra domains federated to GoDaddy. Unlike its predecessor, NovaCookies employs a fully managed phishing-as-a-service (PhaaS) model, centralizing infrastructure management.
Many of the lure domains associated with NovaCookies have been found on the “.vu” domain, using alternating-case labels to mimic legitimate Microsoft services. One attack chain utilizes Docusign notifications as decoys, bypassing sender-authentication checks by leveraging the authenticity of the Docusign email.
The phishing infrastructure is designed to capture credentials and session information in real-time, employing various anti-analysis checks to evade detection by security scanners. This includes mechanisms to detect debugging tools and a Cloudflare gate to obscure the phishing pages.
The emergence of NovaCookies highlights the ongoing evolution of phishing toolkits, which continue to be a lucrative service in the cybercrime underground, enabling even those with minimal technical skills to launch sophisticated phishing campaigns.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



