AI Security AI安全 7h ago Updated 1h ago 更新于 1小时前 41

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions NovaCookies 活动滥用真实 Docusign 通知窃取 Microsoft 365 会话

NovaCookies is a subscription-based adversary-in-the-middle (AitM) phishing toolkit priced at $320/month, designed to steal Microsoft 365 authenticated sessions in real time Attackers leverage genuine Docusign notifications as delivery vectors, embedding malicious links inside legitimate document-share lures to bypass sender-authentication and reputation checks The toolkit uses a multi-hop redirect chain routing through legitimate Microsoft/Google sign-in endpoints before reaching attacker-contr NovaCookies是一个订阅制($320/月)的AitM钓鱼工具包,专门用于窃取Microsoft 365认证会话,已针对美、英、加、德、以、阿联酋等国的数百个组织发动攻击 攻击者利用真实的Docusign通知作为诱饵载体,将恶意链接隐藏在文档内部,结合OAuth错误重定向技术绕过邮件安全产品检测 该工具包是Sneaky 2FA的变体,采用集中式托管的PhaaS模式,支持Microsoft 365、Okta及GoDaddy federated Entra等多种身份提供商 NovaCookies内置Cloudflare gate和反调试检测等反分析机制,域名多托管于".vu"后缀,URL采用

62
Hot 热度
58
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • NovaCookies is a subscription-based adversary-in-the-middle (AitM) phishing toolkit priced at $320/month, designed to steal Microsoft 365 authenticated sessions in real time
  • Attackers leverage genuine Docusign notifications as delivery vectors, embedding malicious links inside legitimate document-share lures to bypass sender-authentication and reputation checks
  • The toolkit uses a multi-hop redirect chain routing through legitimate Microsoft/Google sign-in endpoints before reaching attacker-controlled infrastructure, making each individual hop appear trustworthy
  • NovaCookies is assessed as a variant of the Sneaky 2FA kit, expanded to support additional identity providers including Okta and Entra domains federated to GoDaddy, under a fully managed phishing-as-a-service model
  • The service includes anti-analysis protections such as Cloudflare gates and debugging-tool detection, and operates via Telegram for affiliate management and support

Why It Matters

NovaCookies exemplifies the growing sophistication of phishing-as-a-service (PhaaS) platforms that lower the barrier to entry for credential theft at scale, enabling even non-technical actors to conduct targeted AitM attacks against enterprise Microsoft 365 environments. The use of legitimate third-party services like Docusign as delivery vectors highlights a critical gap in email security architectures that inspect sender reputation but cannot fully validate the content embedded within trusted document-sharing platforms.

Technical Details

  • NovaCookies operates as a live AitM relay proxy, intercepting and forwarding Microsoft 365 authentication traffic between victims and Microsoft's servers in real time, capturing session cookies after password and MFA code entry
  • The primary attack chain uses genuine Docusign envelope notifications containing counterfeit document-share lures; the malicious URL is embedded inside the shared document, positioned below the inspection layer of most mail security products
  • Redirect hops route through legitimate Microsoft or Google sign-in endpoints before reaching the phishing infrastructure, exploiting the OAuth error-redirect technique disclosed by Microsoft in March 2025
  • The toolkit supports multiple identity providers beyond Microsoft, including Okta and Entra domains federated to GoDaddy, indicating a broadened scope compared to the original Sneaky 2FA kit
  • Anti-analysis measures include a Cloudflare gate and detection mechanisms for debugging tools, preventing security scanners and researchers from easily analyzing the phishing pages before they serve the fake Microsoft 365 login form
  • Lure domains are predominantly hosted on the ".vu" TLD with alternating-case URL labels (e.g., PwPt-sHaRe, Ms36-AcCeSs) designed to mimic legitimate Microsoft service naming conventions
  • The PhaaS model is fully managed, with infrastructure hosted centrally by the operator rather than distributed across affiliates, streamlining deployment and reducing operational complexity for buyers

Industry Insight

  • Organizations should implement conditional access policies and continuous access evaluation (CAE) for Microsoft 365 to detect and revoke suspicious sessions in real time, as traditional perimeter defenses cannot prevent AitM session theft once credentials are captured
  • Security teams should enhance email security monitoring to inspect not only sender reputation and authentication protocols (SPF, DKIM, DMARC) but also the content and embedded links within documents shared through trusted third-party platforms like Docusign
  • The proliferation of AI-powered PhaaS and vishing-as-a-service platforms (e.g., AnonyMousKIT, p1bot.io, ATHR) signals a rapid commoditization of advanced attack capabilities, necessitating increased investment in user awareness training focused on recognizing multi-hop redirect chains and unexpected document-share notifications from trusted services

TL;DR

  • NovaCookies是一个订阅制($320/月)的AitM钓鱼工具包,专门用于窃取Microsoft 365认证会话,已针对美、英、加、德、以、阿联酋等国的数百个组织发动攻击
  • 攻击者利用真实的Docusign通知作为诱饵载体,将恶意链接隐藏在文档内部,结合OAuth错误重定向技术绕过邮件安全产品检测
  • 该工具包是Sneaky 2FA的变体,采用集中式托管的PhaaS模式,支持Microsoft 365、Okta及GoDaddy federated Entra等多种身份提供商
  • NovaCookies内置Cloudflare gate和反调试检测等反分析机制,域名多托管于".vu"后缀,URL采用交替大小写伪装成合法Microsoft服务

为什么值得看

NovaCookies代表了网络犯罪工具商业化、服务化的最新趋势,大幅降低了钓鱼攻击的技术门槛,使非技术用户也能发起大规模企业级攻击。其利用真实第三方服务(Docusign)作为信任载体的手法,对传统基于邮件安全和身份验证的安全控制提出了严峻挑战。

技术解析

NovaCookies采用Adversary-in-the-Middle(AitM)代理架构,实时中继Microsoft 365认证流量,在受害者输入密码和MFA代码后捕获完整的认证会话。攻击链利用真实的Docusign信封传递伪造的文档共享诱饵,恶意目标隐藏在文档内部,位于大多数邮件安全产品检查层之下。

工具包采用OAuth错误重定向技术将受害者引导至攻击者控制的基础设施,支持多种身份提供商包括Okta和GoDaddy federated Entra域名。与原始Sneaky 2FA不同,NovaCookies采用完全托管的PhaaS模式,基础设施由运营商集中托管而非各附属人员自行部署。

反分析机制包括Cloudflare gate和调试工具执行检测,域名多使用".vu"后缀,URL标签采用交替大小写(如PwPt-sHaRe、Ms36-AcCeSs)伪装成合法Microsoft服务。

行业启示

PhaaS(钓鱼即服务)生态持续繁荣且日益专业化,从NovaCookies到AnonyMousKIT、p1bot.io、ATHR等新兴工具,网络犯罪正快速采用AI驱动的技术(如语音克隆、AI vishing代理),企业需重新评估针对MFA疲劳攻击和会话窃取的综合防护策略。

传统边界安全控制(邮件过滤、URL黑白名单)已不足以应对这种"信任链分段"攻击手法——每个跳转环节单独看都是合法的,只有在浏览器中才串联成完整攻击链,安全团队需要转向基于行为分析和零信任架构的防御思路。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全