NovaCookies Phishing Kit Abuses DocuSign for Microsoft 365 Session Hijacking
A new phishing-as-a-service toolkit, NovaCookies, is leveraging genuine DocuSign notifications to trick users into revealing Microsoft 365 credentials and session cookies.

A sophisticated new phishing-as-a-service (PhaaS) toolkit named NovaCookies is enabling attackers to steal active Microsoft 365 sessions through a novel adversary-in-the-middle (AitM) approach. Priced at $320 per month, this subscription-based platform has already targeted hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E., according to research from Island.
The NovaCookies toolkit distinguishes itself by abusing legitimate DocuSign notifications. Attackers craft counterfeit document-sharing lures within these genuine emails. When a victim clicks the link, they are often routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before landing on attacker-controlled infrastructure. This multi-stage redirection, combined with the trust associated with DocuSign, aims to bypass initial security scrutiny and create a seemingly legitimate authentication flow.
At its core, NovaCookies functions as an AitM phishing kit. It acts as a proxy, relaying the victim's authentication attempts—including passwords and multi-factor authentication (MFA) codes—through the attacker's infrastructure. Once the victim successfully authenticates, the kit captures the resulting session cookie, granting the attacker direct access to the compromised Microsoft 365 account without needing to re-enter credentials.
Evidence suggests NovaCookies is advertised and managed via Telegram, a popular messaging platform. This infrastructure is used for customer profiling, configuring redirect services, and providing support. Proofpoint has identified NovaCookies as a variant of the Sneaky 2FA phishing kit, noting that while the original focused on Microsoft accounts, NovaCookies has expanded to support other identity providers like Okta and Entra domains federated to GoDaddy. Unlike its predecessor, NovaCookies operates as a fully managed PhaaS, with the operator hosting the infrastructure centrally.
Attackers often utilize the .vu domain for their lure domains, employing alternating-case labels such as PwPt-sHaRe or Ms36-AcCeSs to mimic legitimate Microsoft services. The use of genuine DocuSign notifications is particularly effective as it bypasses sender authentication and reputation checks, making the initial lure appear highly trustworthy. The malicious payload is embedded within the shared document, often hidden from basic email security scans.
To further evade detection, NovaCookies incorporates several anti-analysis measures. These include a Cloudflare gate to filter out automated traffic and mechanisms to detect debugging tools or virtualized environments. The kit is designed to make each step of the attack chain appear legitimate in isolation—a trusted delivery service, a familiar identity provider redirect, and a standard sign-in page—only coalescing into a malicious event within the victim's browser.
The emergence of NovaCookies highlights the growing trend of sophisticated PhaaS offerings in the cybercrime underground. These platforms lower the technical barrier for entry, allowing less skilled actors to conduct large-scale, effective phishing campaigns. The toolkit's ability to bypass MFA through session hijacking, coupled with its deceptive use of trusted services like DocuSign, presents a significant and evolving threat to cloud-based productivity suites like Microsoft 365.