NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions
NovaCookies, a subscription-based phishing platform priced at $320 per month, has been actively exploiting DocuSign to steal Microsoft 365 sessions from hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E. According to security firm Island, the toolkit represents a significant threat because it combines legitimate services with attacker-controlled infrastructure in ways that bypass traditional email security checks.
How the Attack Works
The NovaCookies campaigns leverage genuine DocuSign notifications as the entry point, making the initial email appear trustworthy to both users and security systems. The phishing lure typically poses as a document-share notice—for example, claiming an accounting department has shared a remittance-advice PDF. When victims click through, they’re redirected via legitimate Microsoft or Google sign-in endpoints before landing on attacker-controlled pages that host fake login forms impersonating Microsoft 365.
What makes this approach effective is that the malicious content sits below the layer most mail security products inspect. By routing clicks through real authentication endpoints first, the entire chain appears legitimate until the browser reaches the attacker’s infrastructure. The toolkit also includes anti-analysis defenses such as Cloudflare gating and debugging-tool detection to evade security scanners.
Broader Phishing-as-a-Service Trends
The emergence of NovaCookies reflects a troubling shift in the phishing-as-a-service (PhaaS) market. Security researchers note that newer platforms are automating not just the front end of attacks—the lures and credential capture—but also what comes after. Threat actors are increasingly using AI-generated fraud messages, inbox analysis, and stakeholder mapping to turn stolen credentials into actual financial compromises, lowering the skill barrier for cybercriminals with little technical expertise.
Island’s findings underscore how subscription-based phishing kits continue to democratize large-scale attacks. By combining legitimate third-party services like DocuSign with custom infrastructure and anti-detection measures, these platforms enable attackers to mount convincing campaigns that slip past traditional defenses.
المصدر: The Hacker News