By Interestana AI Editorial — AI-drafted, human-overseen. How we report
NovaCookies Abuses Docusign for Microsoft 365 Session Theft

Cybersecurity researchers have detailed a new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies, which is being used to intercept and capture authenticated Microsoft 365 sessions. The toolkit operates as a proxy, redirecting users' sign-in attempts to malicious servers while harvesting the resulting authenticated session tokens. Island, a cybersecurity firm, characterized NovaCookies as a subscription-based phishing platform available for $320 per month, according to a report shared with The Hacker News. This method bypasses traditional multi-factor authentication (MFA) by capturing the entire authenticated session rather than just credentials.
The NovaCookies toolkit specifically leverages legitimate Docusign notification emails to initiate its attack chain. Attackers send phishing emails that appear to be standard Docusign alerts, prompting recipients to click a link to view or sign a document. When a user clicks this link, they are directed to a fake login page designed to mimic the Microsoft 365 authentication portal. Crucially, the attacker's proxy server intercepts the traffic between the user and the legitimate Microsoft 365 service. This allows the attacker to not only capture the username and password but also the session cookies that confirm the user's identity and grant access to their Microsoft 365 account without requiring re-authentication or MFA prompts.
This technique is particularly concerning because it circumvents security measures that are designed to protect against credential stuffing and phishing attacks. By capturing the authenticated session, NovaCookies effectively allows attackers to impersonate the victim and gain full access to their Microsoft 365 environment, which can include sensitive data, emails, and cloud-based applications like OneDrive and SharePoint. The subscription model suggests that this tool is accessible to a wider range of threat actors, potentially increasing the prevalence of such attacks. The report did not specify the exact timeline of NovaCookies' emergence or the number of victims identified to date, but highlighted the sophistication of the toolkit in its ability to maintain persistent access.
Island's analysis indicates that the NovaCookies toolkit is designed for ease of use, enabling less sophisticated attackers to conduct advanced AitM phishing campaigns. The reliance on Docusign notifications as a vector is a strategic choice, as these emails are commonly received and trusted by business users, making them an effective lure. The $320 monthly subscription fee makes this a commercially viable threat for cybercriminals. The implications for organizations using Microsoft 365 are significant, underscoring the need for enhanced endpoint security, user awareness training regarding phishing attempts, and potentially advanced detection mechanisms that can identify session hijacking tactics.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.