NovaCookies Phishing Toolkit Exploits Docusign Notifications to Hijack Microsoft 365 Sessions

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cybersecurity researchers have unveiled a new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies, which is designed to redirect Microsoft 365 sign-ins while capturing authenticated sessions. This toolkit, characterized as a subscription-based phishing platform costing $320 per month, has reportedly targeted hundreds of organizations across various sectors in the U.S., U.K., Canada, Germany, Israel, and the U.A.E.

According to a report shared with The Hacker News, campaigns utilizing NovaCookies have employed genuine Docusign envelopes to carry counterfeit document-share lures. Some clicks are routed through legitimate Microsoft or Google sign-in endpoints, making the phishing attempts appear trustworthy until users reach the attacker-controlled infrastructure.

NovaCookies operates by relaying Microsoft 365 authentication through its infrastructure, allowing it to harvest session data after victims enter their passwords and multi-factor authentication (MFA) codes. Evidence suggests that the toolkit is advertised via Telegram, which is also used for managing customer profiles and support.

Notably, NovaCookies is considered a variant of the Sneaky 2FA phishing kit, with enhancements that include dedicated flows for other identity providers like Okta and Entra domains federated to GoDaddy. Unlike its predecessor, NovaCookies employs a fully managed phishing-as-a-service (PhaaS) model, centralizing infrastructure management.

Many of the lure domains associated with NovaCookies have been found on the “.vu” domain, using alternating-case labels to mimic legitimate Microsoft services. One attack chain utilizes Docusign notifications as decoys, bypassing sender-authentication checks by leveraging the authenticity of the Docusign email.

The phishing infrastructure is designed to capture credentials and session information in real-time, employing various anti-analysis checks to evade detection by security scanners. This includes mechanisms to detect debugging tools and a Cloudflare gate to obscure the phishing pages.

The emergence of NovaCookies highlights the ongoing evolution of phishing toolkits, which continue to be a lucrative service in the cybercrime underground, enabling even those with minimal technical skills to launch sophisticated phishing campaigns.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...

CrowdStrike’s SafeMind Enhances Cyber Defense with Advanced Offensive Techniques

Revolutionizing Cyber Defense: CrowdStrike's SafeMind System In the ever-evolving landscape of cybersecurity, the ability...

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability On May 24, 2026, Roundcube issued a critical security advisory addressing vulnerabilities in its webmail product....