NovaCookies AitM Phishing Kit Steals Microsoft 365 Sessions via Docusign
Cybersecurity researchers at Island have disclosed a subscription-based adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that abuses legitimate Docusign envelopes to harvest Microsoft 365 authentication sessions. Priced at $320 per month, the service operates as a fully managed phishing-as-a-service (PhaaS) platform, with infrastructure hosted centrally by the operator rather than individual affiliates. Campaigns leveraging the kit have already targeted hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E., spanning multiple industry verticals.
The attack chain hinges on genuine Docusign notifications that pass sender-authentication and reputation checks, embedding counterfeit document-share lures below the inspection layer of most mail security products. Recipients are invited to open a remittance-advice PDF that links to a phishing page styled to mimic Microsoft or Google sign-in endpoints. Once victims submit their credentials and multi-factor authentication (MFA) codes, NovaCookies relays the authentication traffic through attacker-controlled proxy infrastructure, capturing the authenticated session cookie in real time. Investigators have traced many lure domains to the .vu top-level domain — including addresses such as "fordmotbvmorcompany[.]vu" — with phishing URLs using alternating-case labels like PwPt-sHaRe, Ms36-AcCeSs, and ClOd-ViEw to masquerade as legitimate Microsoft services. Security teams investigating suspicious domains can use a WHOIS lookup to verify registrant details and flag newly created or anonymized entries.
Proofpoint has assessed NovaCookies as a variant of the Sneaky 2FA phishing kit, noting key divergences: the new variant introduces dedicated authentication flows for Okta and Entra domains federated to GoDaddy, and it is managed entirely by the PhaaS operator via Telegram channels used for customer onboarding, redirect configuration, and support. The phishing URLs also leverage OAuth error-redirect mechanics to chain victims through legitimate Microsoft and Google endpoints before reaching attacker-controlled infrastructure, making the lure appear trustworthy until the final hop. Users concerned about credential exposure can validate their email addresses against known compromises using the email breach checker, while strengthening account defenses with a robust password checker to ensure unique, high-entropy credentials across Microsoft 365, Okta, and federated identity services.