NovaCookies Phishing Toolkit Exploits Docusign Notifications to Hijack Microsoft 365 Sessions

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybersecurity researchers have unveiled a new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies, which is designed to redirect Microsoft 365 sign-ins while capturing authenticated sessions. This toolkit, characterized as a subscription-based phishing platform costing $320 per month, has reportedly targeted hundreds of organizations across various sectors in the U.S., U.K., Canada, Germany, Israel, and the U.A.E.

According to a report shared with The Hacker News, campaigns utilizing NovaCookies have employed genuine Docusign envelopes to carry counterfeit document-share lures. Some clicks are routed through legitimate Microsoft or Google sign-in endpoints, making the phishing attempts appear trustworthy until users reach the attacker-controlled infrastructure.

NovaCookies operates by relaying Microsoft 365 authentication through its infrastructure, allowing it to harvest session data after victims enter their passwords and multi-factor authentication (MFA) codes. Evidence suggests that the toolkit is advertised via Telegram, which is also used for managing customer profiles and support.

Notably, NovaCookies is considered a variant of the Sneaky 2FA phishing kit, with enhancements that include dedicated flows for other identity providers like Okta and Entra domains federated to GoDaddy. Unlike its predecessor, NovaCookies employs a fully managed phishing-as-a-service (PhaaS) model, centralizing infrastructure management.

Many of the lure domains associated with NovaCookies have been found on the “.vu” domain, using alternating-case labels to mimic legitimate Microsoft services. One attack chain utilizes Docusign notifications as decoys, bypassing sender-authentication checks by leveraging the authenticity of the Docusign email.

The phishing infrastructure is designed to capture credentials and session information in real-time, employing various anti-analysis checks to evade detection by security scanners. This includes mechanisms to detect debugging tools and a Cloudflare gate to obscure the phishing pages.

The emergence of NovaCookies highlights the ongoing evolution of phishing toolkits, which continue to be a lucrative service in the cybercrime underground, enabling even those with minimal technical skills to launch sophisticated phishing campaigns.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cybercriminals Leak Grand Theft Auto VI Footage, Prompting Legal Action from Take-Two Interactive

Grand Theft Auto VI, anticipated as the game event of the decade, faced a major setback last week when a cybercriminal leaked gameplay footage...

Cybersecurity Patch Window Collapses, Urging New Control Strategies for Risk Management

For decades, cybersecurity defenders have relied on a straightforward model: when a vulnerability is disclosed, security teams assess exposure, test fixes, deploy patches, and...

Tehran-linked hackers shut down UK power plant in recent cyber attack

A recent cyber attack attributed to hackers linked to the Iranian regime has resulted in the shutdown of a small power plant in the...

AI-Enabled Malware Analysis Reveals 97% Remains in Research Environments, with Limited Production Activity

  AI-Enabled Malware Analysis: Limited Production Activity Observed Research conducted by Palo Alto Networks reveals that while AI-enabled malware is a growing concern, approximately 97% of...