Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations using Microsoft 365, Okta, or Entra ID
Incident: Deployment of the NovaCookies AitM phishing kit to steal authenticated session tokens.
Impact: Full account compromise and unauthorized access to corporate data by bypassing MFA.
Attacker: NovaCookies PhaaS operators
Analysis: NovaCookies is a Phishing-as-a-Service (PhaaS) toolkit that employs Adversary-in-the-Middle (AitM) techniques to bypass multi-factor authentication. By using legitimate DocuSign envelopes as lures, the campaign effectively evades many traditional email security filters. The operation scales via Telegram, providing affiliates with managed infrastructure to target Microsoft 365, Okta, and Entra ID users.
Recommendations: Transition to FIDO2-compliant hardware security keys to prevent AitM session theft.; Educate employees to verify the legitimacy of document links even when received via trusted services.; Monitor authentication logs for unusual session token activity and unexpected geographic logins.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source