A new phishing toolkit called NovaCookies is being used by cybercriminals to steal Microsoft 365 sessions through advanced phishing attacks. Security researchers found that the service acts as a proxy between victims and legitimate Microsoft login pages. It can capture authenticated sessions after victims enter their passwords and complete MFA. The campaign has targeted organizations across multiple industries and countries.

NovaCookies is offered as a phishing-as-a-service platform, allowing attackers to launch campaigns without building the complete infrastructure themselves. Researchers found the service advertised for $320 per month, with a 14-day option available for $200. The package provides domains, hosting, redirects and other tools required for phishing operations. This makes sophisticated attacks easier for less technically skilled criminals.

One campaign uses genuine DocuSign notifications to make the phishing attempt appear legitimate and familiar. Victims receive a real DocuSign email containing a fake document-sharing message and are encouraged to open the document. The document then directs them toward the attacker’s phishing infrastructure. Using a trusted service in this way can make the initial message harder for victims and security systems to recognize as malicious.

The attack goes beyond simply stealing usernames and passwords from victims. NovaCookies uses an adversary-in-the-middle technique that relays the Microsoft 365 authentication process in real time. Victims can be taken through legitimate Microsoft or Google services before reaching attacker-controlled infrastructure. Once the victim completes MFA, the attackers can capture the authenticated session and potentially use it to access Microsoft 365 resources.

Researchers also found that NovaCookies uses several techniques designed to avoid detection and analysis. These include browser checks, proof-of-work mechanisms, short-lived session binding and other runtime controls. Its infrastructure expanded significantly from mid-May 2026 and continued appearing through August. Researchers identified hundreds of domains connected to the malicious infrastructure, with many observed phishing campaigns using .vu domains.

The discovery shows how modern phishing campaigns are becoming more focused on stealing active authentication sessions rather than only passwords. NovaCookies does not require Microsoft or DocuSign to be compromised because it abuses their legitimate services as part of the attack chain. Security researchers recommend stronger phishing-resistant authentication and continued awareness of suspicious document-sharing messages. The campaign demonstrates why completing MFA alone does not always mean an authentication session is safe.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news