< Back to all clusters
[TECHNOLOGY] · United States, United Kingdom, Canada, Germany, Israel · 2 sources

started · updated

NovaCookies phishing toolkit targets Microsoft 365 sessions

Cybersecurity researchers have identified a new phishing-as-a-service (PhaaS) toolkit named NovaCookies, which is designed to steal authenticated Microsoft 365 sessions in real time. Operating on a subscription model for approximately $320 per month, the service allows attackers to bypass multi-factor authentication (MFA) using adversary-in-the-middle (AiTM) techniques. By intercepting credentials and MFA codes as they are entered, the kit captures session tokens, allowing unauthorized access without needing a password.

Research from Island indicates that NovaCookies has targeted hundreds of organizations across various sectors in the United States, United Kingdom, Canada, Germany, Israel, and the United Arab Emirates. Some campaigns have utilized genuine Docusign notifications to lure victims with counterfeit document-sharing requests.

Proofpoint has assessed NovaCookies as a variant of the Sneaky 2FA phishing kit. While the original focused primarily on Microsoft accounts, NovaCookies includes dedicated flows for other identity providers, such as Okta and Entra domains federated to GoDaddy. The platform is reportedly managed and advertised via Telegram.

Entities

DocuSign · Island · Microsoft 365 · NovaCookies · Proofpoint