'NovaCookies' Phishing Kit Lets Criminals Hijack Microsoft 365 Accounts for $320 a Month
A newly identified phishing-as-a-service kit, dubbed 'NovaCookies,' is being sold to cybercriminals for around $320 a month, according to Dark Reading. The tool uses an adversary-in-the-middle (AitM) technique, which sits between a victim and a legitimate login page to intercept not only usernames and passwords but also active session cookies.
Stealing session cookies is particularly dangerous because it can allow attackers to bypass multi-factor authentication (MFA) altogether. Rather than needing a stolen password and a one-time code, criminals can use a hijacked session token to access Microsoft 365 accounts as if they were the legitimate user, all while security teams see nothing unusual beyond a valid login.
The availability of subscription-based kits like NovaCookies lowers the technical skill needed to launch sophisticated phishing campaigns, making these attacks accessible to a much wider pool of criminals. For small and medium businesses relying on Microsoft 365 for email and collaboration, this represents a growing risk that traditional password and MFA defences alone may not fully address.