Threat Intelligence

New Phishing Toolkit 'NovaCookies' Hijacks Microsoft 365 Logins via Fake Docusign Alerts

The Hacker News · 26 Aug 2026
Key Takeaway Train staff to scrutinise unexpected Docusign or sign-in related emails closely, and consider security tools that detect session hijacking, since MFA alone may not stop these advanced phishing attacks.

Security researchers have uncovered a new phishing-as-a-service toolkit named NovaCookies, which is being sold for around $320 a month to cybercriminals looking to steal Microsoft 365 login credentials and active sessions. The toolkit works as an adversary-in-the-middle (AitM) proxy, meaning it sits between a victim and the real Microsoft sign-in page, silently capturing usernames, passwords, and session cookies as they're entered — even if multi-factor authentication is used.

According to the researchers, attackers are luring victims using what appear to be genuine Docusign notification emails, a tactic designed to build trust and bypass suspicion since Docusign is a widely used and recognised business tool. Once a victim clicks through and signs in, the toolkit captures their authenticated session, potentially giving attackers access to email, files, and other Microsoft 365 services without needing to know the password again.

This type of attack is particularly dangerous for small and medium businesses because it can defeat multi-factor authentication protections that many organisations rely on as a primary defence. As phishing kits like NovaCookies become cheaper and easier to access, even less technically skilled criminals can launch convincing, large-scale attacks against business email systems.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.