New Phishing Toolkit 'NovaCookies' Hijacks Microsoft 365 Logins via Fake Docusign Alerts
Security researchers have uncovered a new phishing-as-a-service toolkit named NovaCookies, which is being sold for around $320 a month to cybercriminals looking to steal Microsoft 365 login credentials and active sessions. The toolkit works as an adversary-in-the-middle (AitM) proxy, meaning it sits between a victim and the real Microsoft sign-in page, silently capturing usernames, passwords, and session cookies as they're entered — even if multi-factor authentication is used.
According to the researchers, attackers are luring victims using what appear to be genuine Docusign notification emails, a tactic designed to build trust and bypass suspicion since Docusign is a widely used and recognised business tool. Once a victim clicks through and signs in, the toolkit captures their authenticated session, potentially giving attackers access to email, files, and other Microsoft 365 services without needing to know the password again.
This type of attack is particularly dangerous for small and medium businesses because it can defeat multi-factor authentication protections that many organisations rely on as a primary defence. As phishing kits like NovaCookies become cheaper and easier to access, even less technically skilled criminals can launch convincing, large-scale attacks against business email systems.