Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Threat Intelligence
  5. NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Scheduled Pinned Locked Moved Threat Intelligence
microsoft
1 Posts 1 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Security researchers have uncovered a new adversary-in-the-middle (AitM) phishing toolkit dubbed NovaCookies, which is being leveraged in active campaigns that abuse legitimate Docusign notifications to intercept Microsoft 365 authentication sessions.

    According to a report from Island, shared ahead of publication, NovaCookies operates as a subscription-based phishing platform priced at $320/month. The service functions as a proxy, sitting between the victim and genuine Microsoft 365 sign-in pages to capture authenticated session cookies in real time.

    • The attacks begin with a legitimate-looking Docusign notification, often forwarded or spoofed, to lure targets into clicking a link.

    • Victims are then redirected through a malicious proxy that relays their login request to the real Microsoft 365 service.

    • Once the victim authenticates, NovaCookies captures the session token, allowing the attacker to maintain access even after the victim logs out.

    • The phishing kit is rented as a service, lowering the technical barrier for aspiring attackers.

    • Campaigns appear focused on organizations relying on Microsoft 365 for email and collaboration.

    • The abuse of genuine Docusign notifications adds a layer of trust, making the phishing attempt harder to detect.

    To reduce exposure, organizations should enforce phishing-resistant multi-factor authentication (MFA), such as FIDO2 security keys, and monitor for unusual session activity or impossible travel patterns.

    Source: The Hacker News

    Has your organization taken steps to harden Microsoft 365 sessions against AitM phishing toolkits like NovaCookies?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World