Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2567+ Articles
161+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
NEWS

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

A $320/month AitM phishing kit rides real Docusign notification emails to relay Microsoft 365 logins and steal live session cookies.

Dylan H.

News Desk

August 26, 2026
3 min read

Overview

Cybersecurity researchers at Proofpoint have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that proxies Microsoft 365 sign-ins to capture both credentials and live authenticated sessions. The toolkit is sold as a subscription service for roughly $320 per month and advertised through Telegram, where buyers manage phishing profiles, configure redirects, and get vendor support like any other SaaS product.

Proofpoint assesses NovaCookies as a variant of the previously documented Sneaky 2FA phishing kit.


How the Campaign Works

NovaCookies' defining trick is that its lures ride on genuine Docusign envelope notifications rather than spoofed ones. Campaigns are styled as routine document-share notices — for example, an email claiming an accounting department has shared a remittance-advice PDF — sent through Docusign's real infrastructure. Because the notification itself is authentic, it passes checks that would flag a forged sender domain.

The malicious destination link is concealed "below the layer most mail security products inspect," according to Proofpoint, letting it slip past automated scanning that stops at the visible, legitimate Docusign content.

Once clicked, victims are routed through a chain of redirects — including legitimate Microsoft or Google sign-in endpoints — before landing on an attacker-controlled AitM proxy. Because each hop in the chain independently resolves to a trustworthy service, the overall path is harder for both users and automated defenses to flag as malicious.

AitM Session Theft

NovaCookies operates as a live relay: it sits between the victim and the real Microsoft 365 login flow, passing through password and MFA prompts in real time while capturing the resulting authenticated session cookie. That cookie theft is what makes AitM kits dangerous even against accounts protected by multi-factor authentication — the attacker doesn't need to defeat MFA, only to be a silent relay for it.


Technical Indicators

  • Phishing domains hosted on the .vu top-level domain (e.g., fordmotbvmorcompany[.]vu)
  • Alternating-case URL path labels designed to imitate Microsoft branding (PwPt-sHaRe, Ms36-AcCeSs, ClOd-ViEw)
  • Abuse of the OAuth error-redirect technique to bounce victims toward attacker infrastructure
  • Anti-analysis measures including Cloudflare gating and detection of browser debugging tools
  • Support for phishing against Microsoft, Okta, and GoDaddy-federated Entra identity providers

Scope and Targeting

Proofpoint reports NovaCookies campaigns have targeted hundreds of organizations across the United States, United Kingdom, Canada, Germany, Israel, and the United Arab Emirates. No single threat actor or nation-state group has been named as the operator — NovaCookies is sold as a commodity kit to any paying customer, broadening the pool of who can run these campaigns.


Mitigation

  1. Treat Docusign and other document-sharing notifications with the same scrutiny as any sign-in prompt — hover and verify destination URLs before entering credentials, even when the surrounding email is legitimate.
  2. Deploy phishing-resistant authentication (FIDO2/WebAuthn hardware keys or platform passkeys) where possible — AitM relays that merely proxy password-and-MFA flows cannot replay a hardware-bound cryptographic assertion.
  3. Enable session-token binding and Conditional Access sign-in risk policies in Microsoft Entra ID to detect and block session cookies used from anomalous locations or devices.
  4. Monitor for the identified indicators — .vu domains, alternating-case Microsoft-lookalike URL paths, and unexpected OAuth error-redirect chains — in email and web proxy logs.
  5. Educate users that a legitimate sender or service (like Docusign) does not guarantee a legitimate destination once a link is clicked, since AitM kits deliberately exploit that trust.

Sources

  • The Hacker News — NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
#Phishing#Microsoft#AitM#Docusign#Session Hijacking#Nation-State

Related Articles

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

New research from CTM360 shows that phishing campaigns targeting insurance and financial portals have moved beyond simple credential harvesting. Attackers...

5 min read

FBI Warns of Kali365 Phishing-as-a-Service Targeting

The FBI has published an advisory on Kali365, a Telegram-based phishing-as-a-service platform that captures legitimate OAuth tokens to gain persistent...

5 min read

Apple Account Change Alerts Abused to Send Phishing Emails

Threat actors are exploiting Apple's legitimate account change notification system to embed fake iPhone purchase scams inside genuine Apple emails,...

4 min read
Back to all News