Cybersecurity researchers disclosed details about a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies. The NovaCookies phishing proxy works by redirecting Microsoft 365 sign-ins through attacker-controlled infrastructure while simultaneously capturing the resulting authenticated session.
According to researchers, the operation has been used in campaigns targeting hundreds of organizations across multiple countries, including the U.S., the U.K., Canada, Germany, Israel, and the U.A.E. The reported lures rely on recognizable document-sharing workflows and redirect behavior that can look legitimate until the browser reaches attacker systems.
What the NovaCookies phishing proxy does
In AitM phishing, the victim’s login flow is relayed so attackers can harvest authentication artifacts. The NovaCookies phishing proxy is designed to pass Microsoft 365 authentication through infrastructure controlled by the threat actor, enabling the attackers to collect session information after the victim enters their password and multi-factor authentication (MFA) code.
Researchers describe NovaCookies as subscription-based, positioning it as a phishing service that supports real-time session theft. Instead of only collecting credentials, the kit aims to take advantage of the authenticated state that forms once the sign-in completes successfully.
Docusign-style notifications as convincing lures
A key theme in observed campaigns is the use of genuine Docusign envelopes and look-alike document-sharing prompts. The emails and document-service context are intended to reduce suspicion, so recipients are more likely to click through.
In the reported flow, the attacker message, the document-sharing component, and the subsequent redirect chain can each appear trustworthy on their own. Researchers noted that some clicks are routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching NovaCookies-controlled infrastructure. That staged approach can make the overall event harder to notice.
One described decoy is styled as a Docusign share notice claiming an accounting department shared a remittance-advice PDF. The malicious content is placed inside the document so it may evade parts of mail security inspection that focus on links visible in the message body.
How the redirect chain makes the attack look normal
NovaCookies is not just a static landing page. It is built to make each step seem normal from the user’s perspective and from the perspective of security tooling that evaluates individual components.
Researchers reported that the kit can present a sequence of “hops” where each hop may look legitimate in isolation: a trusted delivery service, a redirect associated with an identity provider, and then a familiar sign-in interface. The browser ultimately combines these elements into a single event that the attacker infrastructure can then use to harvest session data.
This design goal helps the NovaCookies phishing proxy blend into standard authentication journeys rather than drawing attention with obvious anomalies at every stage.
Real-time session capture via AitM relays
After the victim reaches attacker-controlled infrastructure, NovaCookies operates as a live AitM relay. The kit captures credentials and session details, and it relays authentication to Microsoft in real time. That means the attackers benefit from the same authentication outcome the victim expects—while the attackers gain the session artifacts necessary for misuse.
Researchers also referenced an OAuth error-redirect technique described by Microsoft earlier in the year, which is used to push victims toward attacker-controlled systems.
Managed phishing-as-a-service and affiliate model
Proofpoint assessed NovaCookies as a variant related to the Sneaky 2FA phishing kit. However, the reported differences highlight a shift toward a more centralized service model.
Unlike earlier iterations, NovaCookies is described as operating under a fully managed phishing-as-a-service (PhaaS) structure. Affiliates reportedly pay to use the PhaaS platform, while infrastructure is hosted centrally by the operator rather than being built and maintained by each affiliate.
Operationally, researchers also indicated that the service is promoted via Telegram. Telegram messaging is used both for advertising and for managing elements such as customer profiles, redirect services, and support contact.
Identity-provider coverage and domain tricks
Researchers observed that NovaCookies includes dedicated flows beyond Microsoft accounts. Reported identity-provider coverage includes Okta and Entra domains that are federated to GoDaddy.
To improve disguise, lure URLs and related labels may include alternating-case patterns intended to resemble legitimate Microsoft services. Some lure domains were also reported to use the “.vu” top-level domain (examples in the report include domains using that suffix).
Evasion features built into the kit
Beyond redirect behavior, NovaCookies reportedly includes anti-analysis and anti-scanning mechanisms. Researchers described measures intended to delay or frustrate automated security checks before presenting a fraudulent login prompt that impersonates Microsoft 365.
Examples mentioned in the disclosure include a Cloudflare gate and a mechanism designed to detect execution paths associated with debugging tools.
The overall objective is consistent: ensure the NovaCookies phishing proxy functions smoothly for real users while remaining less visible to automated analysis and some defensive inspection workflows.
Why phishing-as-a-service keeps scaling
The disclosure also sits within a broader trend: PhaaS toolkits continue to be monetized subscription services in the cybercrime ecosystem. The business model lowers the skill barrier for affiliates, allowing them to run campaigns at scale without needing deep expertise in every piece of the attack chain.
Researchers provided additional examples of other offerings that appeared in recent months, including services focused on vishing, automated website template generation, AI-enabled voice scams, credential harvesting panels, and token-based harvesting approaches across various identity and payment-related targets.
This environment matters because it increases the number of actors able to deploy convincing lures and session theft strategies quickly—especially when kits are packaged with infrastructure, redirect logic, and operational support.
Related abuse of legitimate accounts for delivery
Alongside NovaCookies, researchers described another activity attributed to a threat actor tracked as DOUBLOON DREDGER. Observations included abusing Notion accounts to invite targets to view a PDF containing a malicious link.
Security researchers suggested the attacker used Notion to obtain access to a legitimate email sender identity, reputable infrastructure, and a place to host a malicious PDF. The PDF builder reportedly includes overlapping links, a tactic that can help evade defensive tooling and potentially extend the usefulness of a malicious file by providing redundant pathways.
In addition, the landing pages described in that context used techniques for JavaScript obfuscation and encryption, similar to patterns seen in other device-code harvesting campaigns.
Takeaways for organizations using Microsoft 365
The core risk exposed by the NovaCookies phishing proxy campaign is that MFA and familiar sign-in experiences do not necessarily stop session theft when an AitM relay is involved. If attackers can route a victim through attacker-controlled infrastructure in real time, they may still obtain authenticated session value.
Organizations should consider strengthening controls around user access and sign-in workflows, including monitoring for unusual redirect patterns, enforcing additional verification for sensitive actions, and validating that document-sharing or envelope notifications align with expected business processes.
Because the campaigns leverage recognizable services and trusted-looking delivery flows, awareness training also remains important—especially for teams that commonly receive document requests, shared PDFs, or invoice-related notifications.
Conclusion
The findings show how the NovaCookies phishing proxy uses a sophisticated AitM approach to redirect Microsoft 365 sign-ins and harvest authenticated sessions. By combining Docusign-style notifications, staged redirect hops, and centralized phishing-as-a-service infrastructure, the operation aims to keep the attack looking ordinary until it reaches attacker-controlled systems.
As PhaaS offerings continue to mature, the best defense is a layered one: improved monitoring of authentication flows, stricter verification for unusual document-sharing requests, and continuous user awareness for phishing attempts that masquerade as legitimate business communication.
Source: https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html
