NovaCookies Phishing Toolkit Exploits Docusign Notifications to Hijack Microsoft 365 Sessions

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybersecurity researchers have unveiled a new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies, which is designed to redirect Microsoft 365 sign-ins while capturing authenticated sessions. This toolkit, characterized as a subscription-based phishing platform costing $320 per month, has reportedly targeted hundreds of organizations across various sectors in the U.S., U.K., Canada, Germany, Israel, and the U.A.E.

According to a report shared with The Hacker News, campaigns utilizing NovaCookies have employed genuine Docusign envelopes to carry counterfeit document-share lures. Some clicks are routed through legitimate Microsoft or Google sign-in endpoints, making the phishing attempts appear trustworthy until users reach the attacker-controlled infrastructure.

NovaCookies operates by relaying Microsoft 365 authentication through its infrastructure, allowing it to harvest session data after victims enter their passwords and multi-factor authentication (MFA) codes. Evidence suggests that the toolkit is advertised via Telegram, which is also used for managing customer profiles and support.

Notably, NovaCookies is considered a variant of the Sneaky 2FA phishing kit, with enhancements that include dedicated flows for other identity providers like Okta and Entra domains federated to GoDaddy. Unlike its predecessor, NovaCookies employs a fully managed phishing-as-a-service (PhaaS) model, centralizing infrastructure management.

Many of the lure domains associated with NovaCookies have been found on the “.vu” domain, using alternating-case labels to mimic legitimate Microsoft services. One attack chain utilizes Docusign notifications as decoys, bypassing sender-authentication checks by leveraging the authenticity of the Docusign email.

The phishing infrastructure is designed to capture credentials and session information in real-time, employing various anti-analysis checks to evade detection by security scanners. This includes mechanisms to detect debugging tools and a Cloudflare gate to obscure the phishing pages.

The emergence of NovaCookies highlights the ongoing evolution of phishing toolkits, which continue to be a lucrative service in the cybercrime underground, enabling even those with minimal technical skills to launch sophisticated phishing campaigns.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...