Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions

NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions

Posted on August 26, 2026 By CWS

Cybersecurity specialists have unveiled NovaCookies, a novel adversary-in-the-middle phishing toolkit that reroutes Microsoft 365 logins, capturing authenticated sessions along the way.

Subscription-Based Phishing Platform

Island, in a report shared with The Hacker News, described NovaCookies as a $320/month service functioning as a subscription-based phishing platform. This toolkit has been utilized against numerous organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E. It employs legitimate Docusign notifications to disguise its phishing attempts, making them appear credible until users are redirected to attacker-controlled infrastructure.

Functionality and Infrastructure

NovaCookies is engineered to intercept Microsoft 365 authentication via attacker-controlled systems, acting as a proxy to harvest session data. Evidence suggests that NovaCookies is promoted on Telegram, which also serves as a platform for managing user profiles and support services. Proofpoint has assessed that NovaCookies is a variant of the Sneaky 2FA phishing kit, featuring flows for various identity providers like Okta and Entra domains associated with GoDaddy.

Unlike its predecessor, Sneaky2FA, NovaCookies operates under a fully managed phishing-as-a-service model, centralizing its infrastructure rather than relying on individual affiliates. The phishing URLs often appear under the “.vu” domain, with deceptive labels to mimic legitimate Microsoft services.

Technical Tactics and Implications

One of NovaCookies’ strategies involves using genuine Docusign notifications to lure victims to phishing sites, circumventing typical sender-authentication checks. The phishing infrastructure employs OAuth error-redirect techniques to lead users to malicious sites. The service also includes anti-analysis measures to evade detection, such as Cloudflare gates and debugging tool detection.

NovaCookies’ effectiveness lies in its ability to make each step of the attack seem trustworthy, from the delivery service to the identity-provider redirect, culminating in a familiar sign-in page. This makes it challenging for security tools to identify the threat until it’s too late.

Emerging PhaaS Threats and Market Trends

The disclosure of NovaCookies coincides with the rise of PhaaS toolkits, which have become lucrative in cybercrime. These platforms allow even those with minimal technical skills to launch extensive phishing campaigns. New services like AnonyMousKIT, p1bot.io, and Bluekit showcase the evolving landscape, utilizing AI and advanced tactics to enhance phishing capabilities.

Moreover, threat actors like DOUBLOON DREDGER exploit platforms such as Notion to deliver malicious content, using overlapping links and obfuscation techniques to evade detection. This shift highlights the increasing sophistication and accessibility of phishing operations, posing significant challenges for cybersecurity defenses.

EvilTokens, another PhaaS service, marks a notable shift by automating post-compromise actions, further lowering the skill barrier for executing successful cyber fraud. Such developments underscore the need for heightened vigilance and advanced defensive strategies in the face of evolving threats.

The Hacker News Tags:AiTM, Cybersecurity, Docusign, Microsoft 365, NovaCookies, PhaaS, Phishing, session theft, Sneaky 2FA, Telegram

Post navigation

Previous Post: 24 Malicious npm Packages Exploit Mirrors for Phishing
Next Post: OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign

Related Posts

Learn How Leading Security Teams Blend AI + Human Workflows (Free Webinar) Learn How Leading Security Teams Blend AI + Human Workflows (Free Webinar) The Hacker News
APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign The Hacker News
AI Tool Uncovers New HTTP Desync Methods and Apache Flaw AI Tool Uncovers New HTTP Desync Methods and Apache Flaw The Hacker News
EngageLab SDK Vulnerability Risks Millions of Android Users EngageLab SDK Vulnerability Risks Millions of Android Users The Hacker News
ServiceNow AI Platform Security Flaw Under Attack ServiceNow AI Platform Security Flaw Under Attack The Hacker News
Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure
  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
  • NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure
  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
  • NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark