Cybersecurity specialists have unveiled NovaCookies, a novel adversary-in-the-middle phishing toolkit that reroutes Microsoft 365 logins, capturing authenticated sessions along the way.
Subscription-Based Phishing Platform
Island, in a report shared with The Hacker News, described NovaCookies as a $320/month service functioning as a subscription-based phishing platform. This toolkit has been utilized against numerous organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E. It employs legitimate Docusign notifications to disguise its phishing attempts, making them appear credible until users are redirected to attacker-controlled infrastructure.
Functionality and Infrastructure
NovaCookies is engineered to intercept Microsoft 365 authentication via attacker-controlled systems, acting as a proxy to harvest session data. Evidence suggests that NovaCookies is promoted on Telegram, which also serves as a platform for managing user profiles and support services. Proofpoint has assessed that NovaCookies is a variant of the Sneaky 2FA phishing kit, featuring flows for various identity providers like Okta and Entra domains associated with GoDaddy.
Unlike its predecessor, Sneaky2FA, NovaCookies operates under a fully managed phishing-as-a-service model, centralizing its infrastructure rather than relying on individual affiliates. The phishing URLs often appear under the “.vu” domain, with deceptive labels to mimic legitimate Microsoft services.
Technical Tactics and Implications
One of NovaCookies’ strategies involves using genuine Docusign notifications to lure victims to phishing sites, circumventing typical sender-authentication checks. The phishing infrastructure employs OAuth error-redirect techniques to lead users to malicious sites. The service also includes anti-analysis measures to evade detection, such as Cloudflare gates and debugging tool detection.
NovaCookies’ effectiveness lies in its ability to make each step of the attack seem trustworthy, from the delivery service to the identity-provider redirect, culminating in a familiar sign-in page. This makes it challenging for security tools to identify the threat until it’s too late.
Emerging PhaaS Threats and Market Trends
The disclosure of NovaCookies coincides with the rise of PhaaS toolkits, which have become lucrative in cybercrime. These platforms allow even those with minimal technical skills to launch extensive phishing campaigns. New services like AnonyMousKIT, p1bot.io, and Bluekit showcase the evolving landscape, utilizing AI and advanced tactics to enhance phishing capabilities.
Moreover, threat actors like DOUBLOON DREDGER exploit platforms such as Notion to deliver malicious content, using overlapping links and obfuscation techniques to evade detection. This shift highlights the increasing sophistication and accessibility of phishing operations, posing significant challenges for cybersecurity defenses.
EvilTokens, another PhaaS service, marks a notable shift by automating post-compromise actions, further lowering the skill barrier for executing successful cyber fraud. Such developments underscore the need for heightened vigilance and advanced defensive strategies in the face of evolving threats.
