NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
NovaCookies is a subscription-based adversary-in-the-middle (AitM) phishing toolkit priced at $320/month, designed to steal Microsoft 365 authenticated sessions in real time Attackers leverage genuine Docusign notifications as delivery vectors, embedding malicious links inside legitimate document-share lures to bypass sender-authentication and reputation checks The toolkit uses a multi-hop redirect chain routing through legitimate Microsoft/Google sign-in endpoints before reaching attacker-contr
Analysis
TL;DR
- NovaCookies is a subscription-based adversary-in-the-middle (AitM) phishing toolkit priced at $320/month, designed to steal Microsoft 365 authenticated sessions in real time
- Attackers leverage genuine Docusign notifications as delivery vectors, embedding malicious links inside legitimate document-share lures to bypass sender-authentication and reputation checks
- The toolkit uses a multi-hop redirect chain routing through legitimate Microsoft/Google sign-in endpoints before reaching attacker-controlled infrastructure, making each individual hop appear trustworthy
- NovaCookies is assessed as a variant of the Sneaky 2FA kit, expanded to support additional identity providers including Okta and Entra domains federated to GoDaddy, under a fully managed phishing-as-a-service model
- The service includes anti-analysis protections such as Cloudflare gates and debugging-tool detection, and operates via Telegram for affiliate management and support
Why It Matters
NovaCookies exemplifies the growing sophistication of phishing-as-a-service (PhaaS) platforms that lower the barrier to entry for credential theft at scale, enabling even non-technical actors to conduct targeted AitM attacks against enterprise Microsoft 365 environments. The use of legitimate third-party services like Docusign as delivery vectors highlights a critical gap in email security architectures that inspect sender reputation but cannot fully validate the content embedded within trusted document-sharing platforms.
Technical Details
- NovaCookies operates as a live AitM relay proxy, intercepting and forwarding Microsoft 365 authentication traffic between victims and Microsoft's servers in real time, capturing session cookies after password and MFA code entry
- The primary attack chain uses genuine Docusign envelope notifications containing counterfeit document-share lures; the malicious URL is embedded inside the shared document, positioned below the inspection layer of most mail security products
- Redirect hops route through legitimate Microsoft or Google sign-in endpoints before reaching the phishing infrastructure, exploiting the OAuth error-redirect technique disclosed by Microsoft in March 2025
- The toolkit supports multiple identity providers beyond Microsoft, including Okta and Entra domains federated to GoDaddy, indicating a broadened scope compared to the original Sneaky 2FA kit
- Anti-analysis measures include a Cloudflare gate and detection mechanisms for debugging tools, preventing security scanners and researchers from easily analyzing the phishing pages before they serve the fake Microsoft 365 login form
- Lure domains are predominantly hosted on the ".vu" TLD with alternating-case URL labels (e.g., PwPt-sHaRe, Ms36-AcCeSs) designed to mimic legitimate Microsoft service naming conventions
- The PhaaS model is fully managed, with infrastructure hosted centrally by the operator rather than distributed across affiliates, streamlining deployment and reducing operational complexity for buyers
Industry Insight
- Organizations should implement conditional access policies and continuous access evaluation (CAE) for Microsoft 365 to detect and revoke suspicious sessions in real time, as traditional perimeter defenses cannot prevent AitM session theft once credentials are captured
- Security teams should enhance email security monitoring to inspect not only sender reputation and authentication protocols (SPF, DKIM, DMARC) but also the content and embedded links within documents shared through trusted third-party platforms like Docusign
- The proliferation of AI-powered PhaaS and vishing-as-a-service platforms (e.g., AnonyMousKIT, p1bot.io, ATHR) signals a rapid commoditization of advanced attack capabilities, necessitating increased investment in user awareness training focused on recognizing multi-hop redirect chains and unexpected document-share notifications from trusted services
Disclaimer: The above content is generated by AI and is for reference only.