Threat Intelligence

'NovaCookies' Phishing Kit Lets Criminals Hijack Microsoft 365 Accounts for $320 a Month

Dark Reading · 26 Aug 2026
Key Takeaway Don't rely on passwords and MFA alone — monitor for suspicious session activity and train staff to recognise convincing fake login pages, since session-hijacking phishing kits can bypass standard MFA protections.

A newly identified phishing-as-a-service kit, dubbed 'NovaCookies,' is being sold to cybercriminals for around $320 a month, according to Dark Reading. The tool uses an adversary-in-the-middle (AitM) technique, which sits between a victim and a legitimate login page to intercept not only usernames and passwords but also active session cookies.

Stealing session cookies is particularly dangerous because it can allow attackers to bypass multi-factor authentication (MFA) altogether. Rather than needing a stolen password and a one-time code, criminals can use a hijacked session token to access Microsoft 365 accounts as if they were the legitimate user, all while security teams see nothing unusual beyond a valid login.

The availability of subscription-based kits like NovaCookies lowers the technical skill needed to launch sophisticated phishing campaigns, making these attacks accessible to a much wider pool of criminals. For small and medium businesses relying on Microsoft 365 for email and collaboration, this represents a growing risk that traditional password and MFA defences alone may not fully address.

phishing Microsoft 365 session hijacking MFA bypass cybercrime-as-a-service

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.