NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

August 26, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations using Microsoft 365, Okta, or Entra ID
Incident: Deployment of the NovaCookies AitM phishing kit to steal authenticated session tokens.
Impact: Full account compromise and unauthorized access to corporate data by bypassing MFA.
Attacker: NovaCookies PhaaS operators
Analysis: NovaCookies is a Phishing-as-a-Service (PhaaS) toolkit that employs Adversary-in-the-Middle (AitM) techniques to bypass multi-factor authentication. By using legitimate DocuSign envelopes as lures, the campaign effectively evades many traditional email security filters. The operation scales via Telegram, providing affiliates with managed infrastructure to target Microsoft 365, Okta, and Entra ID users.
Recommendations: Transition to FIDO2-compliant hardware security keys to prevent AitM session theft.; Educate employees to verify the legitimacy of document links even when received via trusted services.; Monitor authentication logs for unusual session token activity and unexpected geographic logins.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *