NovaCookies Phishing Toolkit Steals Microsoft 365 Sessions via Docusign Notifications
Cybersecurity researchers have discovered a phishing toolkit called NovaCookies that's used to redirect Microsoft 365 sign-ins and capture authenticated sessions. The $320/month service is a subscription-based platform that facilitates real-time Microsoft 365 session theft, targeting hundreds of organizations across multiple sectors in the U.S., the U.K., Canada, Germany, Israel, and the U.A.E.
The toolkit uses genuine Docusign envelopes to carry counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching the kit. NovaCookies is designed to relay Microsoft 365 authentication through attacker-controlled infrastructure, allowing it to act as a proxy and harvest the resulting session after victims enter their passwords and multi-factor authentication (MFA) codes.
The service is advertised via Telegram, with the messaging service also used as infrastructure to manage customer profiles, configure redirect services, and contact support. According to Proofpoint, NovaCookies is assessed to be a variant of the Sneaky 2FA phishing kit, which has expanded its focus from mainly targeting Microsoft accounts to include other identity providers such as Okta and Entra domains federated to GoDaddy.