Phishing Service 'NovaCookies' Steals Microsoft 365 Sessions for $320 a Month
A novel phishing service called 'NovaCookies' is offering attackers a way to steal authenticated Microsoft 365 sessions for just $320 a month, bypassing multifactor authentication (MFA) protections. The service, discovered by researchers from Island, provides lures, domains, hosting, redirects, and support to relay Microsoft 365 logins in real time.
NovaCookies operates like a commercial business, targeting hundreds of organizations across multiple regions, with at least 755 domains as part of its dedicated infrastructure. More than half of these organizations are in the US or related to entities in the country, and the campaign's infrastructure expanded sharply from mid-May through August.
The service includes built-in evasion tactics, such as short-lived context binding and runtime inspection, making the lures resistant to email scanners. Researchers note that attackers can pivot to stealing session cookies rather than just passwords, which is a novel aspect of NovaCookies.