NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
Executive Summary
Cybersecurity researchers revealed NovaCookies, an adversary‑in‑the‑middle phishing toolkit that masquerades as legitimate DocuSign notifications to lure users into Microsoft 365 sign‑ins. The tool acts as a proxy, redirecting authentication traffic and capturing active sessions, enabling attackers to hijack accounts. The service is subscription‑based at $320/month and is sold to threat actors.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-26T13:44:31+00:00 - Category: threat-intel
Original Description: Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that
"Great indeed is the sublimity of the Creative, to which all beings owe their beginning and which permeates all heaven."
— Lao Tzu