Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
nextbyte.live
nextbyte.live
  • Home
  • Home
Subscribe
Close

Search

NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions
cybersecurity

NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions

By abde el aziz
August 26, 2026 2 Min Read
0

NovaCookies, a subscription-based phishing platform priced at $320 per month, has been actively exploiting DocuSign to steal Microsoft 365 sessions from hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E. According to security firm Island, the toolkit represents a significant threat because it combines legitimate services with attacker-controlled infrastructure in ways that bypass traditional email security checks.

How the Attack Works

The NovaCookies campaigns leverage genuine DocuSign notifications as the entry point, making the initial email appear trustworthy to both users and security systems. The phishing lure typically poses as a document-share notice—for example, claiming an accounting department has shared a remittance-advice PDF. When victims click through, they’re redirected via legitimate Microsoft or Google sign-in endpoints before landing on attacker-controlled pages that host fake login forms impersonating Microsoft 365.

What makes this approach effective is that the malicious content sits below the layer most mail security products inspect. By routing clicks through real authentication endpoints first, the entire chain appears legitimate until the browser reaches the attacker’s infrastructure. The toolkit also includes anti-analysis defenses such as Cloudflare gating and debugging-tool detection to evade security scanners.

Broader Phishing-as-a-Service Trends

The emergence of NovaCookies reflects a troubling shift in the phishing-as-a-service (PhaaS) market. Security researchers note that newer platforms are automating not just the front end of attacks—the lures and credential capture—but also what comes after. Threat actors are increasingly using AI-generated fraud messages, inbox analysis, and stakeholder mapping to turn stolen credentials into actual financial compromises, lowering the skill barrier for cybercriminals with little technical expertise.

Island’s findings underscore how subscription-based phishing kits continue to democratize large-scale attacks. By combining legitimate third-party services like DocuSign with custom infrastructure and anti-detection measures, these platforms enable attackers to mount convincing campaigns that slip past traditional defenses.

المصدر: The Hacker News

Author

abde el aziz

Follow Me
Other Articles
Perplexity launches local AI agent for high-end NVIDIA hardware
Previous

Perplexity launches local AI agent for high-end NVIDIA hardware

Meta settles major teen safety lawsuit with 29 US states
Next

Meta settles major teen safety lawsuit with 29 US states

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Motorola Previews Android 15 Update and New Themed Icons
  • Critical Avada WordPress Theme Flaw Allows Zero-Click Remote Code Execution
  • The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent
  • Nvidia Details Groq 3 LPX Architecture and First Third-Party Benchmarks
  • OpenAI Model Escaped Restricted Environment to Hack Hugging Face

Recent Comments

  1. Motorola Previews Android 15 Update and New Themed Icons on Samsung rolls out One UI 9 beta 6 for Galaxy S26 series
  2. Critical Avada WordPress Theme Flaw Allows Zero-Click Remote Code Execution on Meta to Pay $18 Billion to Settle Lawsuit Over Teen Safety Concerns
  3. The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent on Google Pixel 11 Pro Fold Review: A Solid Effort Facing Tough Competition
  4. Nvidia Details Groq 3 LPX Architecture and First Third-Party Benchmarks on NVIDIA Launches DLSS 4.5 Ray Reconstruction for RTX Remix and New Titles
  5. OpenAI Model Escaped Restricted Environment to Hack Hugging Face on How to Automate Dependabot Pull Requests Using GitHub Copilot

Archives

  • August 2026

Categories

  • ai
  • crypto
  • cybersecurity
  • gadgets
  • hardware
  • tech
  • web
Copyright 2026 — nextbyte.live. All rights reserved. Blogsy WordPress Theme