NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process.
In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that facilitates real-time Microsoft 365 session theft. The kit has been used to target hundreds of organizations across multiple sectors in the U.S., the U.K., Canada, Germany, Israel, and the U.A.E. to date.
"Observed campaigns used genuine Docusign envelopes to carry counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching the kit," Island said. "The message, document service and redirect can therefore appear trustworthy until the browser reaches attacker-controlled infrastructure."
Like other AitM phishing kits, NovaCookies is designed to relay Microsoft 365 authentication through attacker-controlled infrastructure, allowing it to act as a proxy and harvest the resulting session after victims enter their passwords and multi-factor authentication (MFA) codes.
Evidence indicates that NovaCookies is advertised via Telegram, with the messaging service also used as infrastructure to manage customer profiles, configure redirect services, and contact support. According to Proofpoint, NovaCookies is assessed to be a variant of the Sneaky 2FA phishing kit.
"While the original Sneaky2FA appeared to focus mainly on Microsoft accounts, the NovaCookies variant includes dedicated flows for other identity providers, including Okta, and Entra domains federated to GoDaddy," Proofpoint noted in an X post last month.
"Unlike Sneaky2FA, NovaCookies uses a fully managed phishing-as-a-service (PhaaS) model where affiliates pay to use a PhaaS platform, and the infrastructure is hosted centrally by the PhaaS operator rather than by each affiliate."
Many NovaCookies lure domains have been found to be hosted on the ".vu" domain (e.g., "fordmotbvmorcompany[.]vu"), with the phishing URLs featuring alternating-case labels such as PwPt-sHaRe, Ms36-AcCeSs, and ClOd-ViEw in an attempt to masquerade as legitimate Microsoft services.
One of the attack chains employs Docusign notifications as decoys to lead victims to the phishing pages, while bypassing sender-authentication and reputation checks by taking advantage of the fact that the email is a genuine Docusign notification. What's malicious is the document shared via the service.
"Styled as a Docusign share notice, it claimed that an accounting department had shared a remittance-advice PDF and invited the recipient to open it," Island said. "The malicious destination sat inside the document, below the layer most mail security products inspect."
The attack then employs an OAuth error-redirect technique detailed by Microsoft earlier this March to lead victims to attacker-controlled infrastructure. The phishing infrastructure operated by NovaCookies is a live AitM relay designed to capture credentials and session information, and relay it to Microsoft in real time.
The commercial offering also boasts of various anti-analysis checks to evade security scanners before serving the bogus login form impersonating Microsoft 365. This includes a Cloudflare gate and a mechanism to detect execution passes associated with debugging tools.
"NovaCookies is built so each hop can look legitimate on its own: a trusted delivery service, an identity-provider redirect, then a familiar sign-in page," Island said. "Those pieces often land in different tools. The browser is where they become a single event."
The disclosure comes as PhaaS toolkits continue to be a lucrative subscription service in the cybercrime underground, allowing cybercriminals with little to no technical expertise to mount phishing campaigns at scale. Some of the new services that have emerged in recent months include -
- AnonyMousKIT, which has been active since early 2024 and uses artificial intelligence (AI)-powered vishing tactics to target stolen device owners by posing as Apple Support and asking them to provide their device passcode, Apple ID, and 6-digit 2FA code on fake domains embedded in emails with the end goal of disabling Activation Lock on the device and reselling it. The service obtains the owner's contact information supplied through the Lost Mode feature, using it to reach out to them through email, SMS, WhatsApp, or a phone call.
- p1bot.io, a vishing-as-a-service platform that uses ElevenLabs' text-to-speech capabilities to generate Interactive Voice Response (IVR) prompts in English, French, or Spanish, play them to victims mid-call, and capture keypad presses (e.g., PINs, OTPs, or account numbers) in real time.
- Bluekit, which advertises 40+ website templates, automated domain purchase and registration, 2FA support, spoofing, geolocation emulation, Telegram and browser notifications, antibot cloaking, and add-ons like an AI assistant, voice cloning, and a mail sender
- ATHR, which uses AI vishing agents, credential harvesting panels, and built-in phishing mailers to execute and scale telephone-oriented attack delivery (TOAD) attacks.
- ZeroTokens, which supports impersonation of 53 financial institution brands to harvest credentials, identity data, payment details, and verification codes. The service makes use of ten sender domains (four ".com" and six ".asia") and nine SendGrid accounts to bypass SPF, DKIM, and DMARC checks.
- iAuthFlow V2, which uses a browser-in-the-middle (BitM) relay to turn a temporary foothold afforded by a phished Google session into persistent access by enrolling an attacker-controlled passkey. It's advertised for $10,000 for the base package, with additional capability modules sold separately, along with other versions for Microsoft, iCloud, and LinkedIn.
- LinXcoded (aka Mirage2FA), which makes use of compromised senders, analysis evasion, and real-time Microsoft 365 relays to capture authenticated sessions. Phishing messages leveraging the kit originate from compromised, authenticated Microsoft 365 tenants and carry the payload as an HTML attachment rather than a link in the message body to evade email security controls.
- Matrix, which shares the same lineage as Sneaky 2FA and enables Microsoft 365 credential-phishing via an AitM harvester. Phishing messages leveraging the kit employ OneDrive notifications that prompt recipients to open a shared document.
- ARToken, which steals Microsoft 365 tokens through the OAuth device code flow and facilitates full account takeover via invoice-themed phishing emails sent from a compromised legitimate Google Workspace or Microsoft 365 mailbox that link to an anonymous SharePoint file share hosted on a compromised third-party tenant. The share contains a Windows Internet Shortcut file that displays an identity-verification prompt to carry out device code phishing.
- Blacksite, which pairs an AitM reverse-proxy kit with Cloaked.gg, a cloaking service, to hide phishing pages from automated URL analysis and serve benign decoys to scanners. The kit is designed to intercept authentication tokens, session cookies, and one-time 2FA codes in real time.
- Balonx Sistema, which is a Mexican PhaaS operation that targets over 20 financial institutions in the country with live WebSocket victim interaction, an integrated Android Remote Access Trojan (RAT) based on Spyroid, and an advanced AI-driven vishing component dubbed CallFlow that automates voice fraud via synthetic speech and large language models (LLMs). More than 1,100 users' credentials and financial information have been collected since at least October 2025.
- EvilTokens, which provides an off-the-shelf Microsoft device code phishing kit and malicious AI-powered analytics services that allow customers to identify valuable data for fraud and scam campaigns.
- Forg365, which combines device code phishing, AitM tactics, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts.
The findings also come as a threat actor tracked as DOUBLOON DREDGER has been observed abusing Notion accounts to invite targets to view a PDF that contains a malicious link, clicking which takes them to an EvilTokens device code harvesting page.
"They abuse Notion to gain access to a legitimate email sender, reputable infrastructure, and a place to host a malicious PDF," Sublime said. "They use a PDF builder that includes two to three overlapping links, attempting to evade defensive tooling and detections while potentially increasing the shelf life of any single malicious PDF with redundant infrastructure."
"The payload landing page uses a JavaScript obfuscation and encryption technique similar to recent Tycoon 2FA device code harvesting campaigns."
It's suspected with low confidence that DOUBLOON DREDGER has acquired access to both EvilTokens and Tycoon 2FA and then uses their own custom first-stage JavaScript in front of the PhaaS kits. The threat actor is believed to be financially motivated.
"EvilTokens represents a structural shift in the PhaaS market. Previous platforms commoditized the front end of the attack: the lure, the landing page, the credential capture," Flare security researcher Assaf Morag said. "EvilTokens commoditizes what comes after."
"By automating inbox analysis, stakeholder mapping, and AI-generated fraud messages, it removes the skill barrier that once separated a captured token from a successful financial compromise. An affiliate no longer needs to understand business email compromise tradecraft, as the platform provides it as a feature."
This article was published by The Hacker News. Please check their website for the original content.