NovaCookies Sells MFA-Bypassing M365 Session Hijack

BeeHiiv Feed 2 · High sophistication
Last updated September 9, 2026

A commercial phishing service called NovaCookies is being marketed as a subscription that can hijack Microsoft 365 sessions even when MFA is enabled. Research describes how it uses legitimate-looking delivery (e.g., real DocuSign envelopes and trusted redirect endpoints) to trick users into completing a real-time sign-in flow that steals their session.

How the Attack Worked

NovaCookies is described as a paid, subscription-style adversary-in-the-middle phishing service built specifically to steal Microsoft 365 sessions, including in environments where MFA is enabled. Rather than trying to guess or brute-force credentials, the service intercepts a real-time sign-in flow. When a target completes what looks like a normal Microsoft 365 login, the attacker captures the resulting session, effectively inheriting access without needing to defeat MFA directly.

The delivery mechanism is designed to look ordinary. Targets receive what appears to be a legitimate DocuSign envelope, a document signature request, which then routes them into a Microsoft 365 sign-in flow. Because the chain uses genuine DocuSign envelopes and trusted Microsoft and Google redirect endpoints, the experience closely mirrors a real, expected business workflow.

Why It Succeeded

The attack's effectiveness comes from combining familiar business processes with technical evasion of MFA protections. Signature requests are routine for many employees, especially in finance, HR, legal, and executive support roles, so an unexpected DocuSign envelope does not automatically stand out as unusual. Layering a real sign-in flow on top of that pretext removes one of the traditional warning signs, an obviously fake login page, since the flow is functionally a real Microsoft 365 authentication.

The operation is also described as industrialized, with rotating infrastructure and an operator dashboard, suggesting a maintained, scalable service rather than a one-off campaign. This kind of infrastructure lets the same techniques be reused across many targets and organizations.

What to Watch For

  • An unexpected DocuSign envelope for a document you were not anticipating
  • A login flow reached through redirects rather than a normal bookmarked Microsoft 365 login page
  • Pressure to sign or review a document quickly without prior context or a related conversation

Building Resistance

Organizations can reduce exposure by encouraging users to verify unexpected signature requests through an independent, known channel, such as calling the sender using a saved phone number rather than replying to the email. Awareness training should also reinforce that MFA does not guarantee protection against session theft: if a user completes a phishing-driven sign-in flow, the resulting session can still be hijacked. Finally, staff across all departments, not just IT, should be trained to treat familiar-looking redirects and trusted-branded links with the same scrutiny as unfamiliar ones, since attackers can and do use legitimate services and redirect endpoints to build credibility.

Key findings

  • NovaCookies is described as a paid, subscription-style adversary-in-the-middle (AiTM) phishing service designed to steal Microsoft 365 sessions, including in MFA-enabled environments.
  • The delivery chain is designed to look legitimate by using real DocuSign envelopes and trusted Microsoft/Google redirect endpoints.
  • The service includes “rotating infrastructure” and “an operator dashboard,” indicating an industrialized, scalable phishing operation.
  • Island Security Research published 755 domains as indicators of compromise (IOCs) (not listed in the newsletter text).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, Legal, IT helpdesk.
  • Affected industries: Multiple industries (hundreds of organizations).
  • Attack channels: email, website.
  • Impersonated: DocuSign (document/signature request) leading into Microsoft 365 login.

Red flags to watch for

  • Unexpected DocuSign envelope you weren’t anticipating
  • Login flow reached via redirects rather than your normal bookmarked Microsoft 365 login
  • Pressure to sign/review a document quickly without context
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does NovaCookies bypass MFA?

It uses an adversary-in-the-middle phishing flow that steals a live Microsoft 365 session after a user completes a real-time sign-in, meaning MFA is satisfied during the attack rather than blocked.

Why do NovaCookies phishing messages look legitimate?

The delivery chain uses real DocuSign envelopes and trusted Microsoft and Google redirect endpoints, making the request appear to come from familiar, expected services.

Does having MFA enabled protect against this attack?

Not fully. Since the attack steals an active session created during a phishing-driven sign-in flow, MFA alone does not prevent account takeover in this scenario.

What roles are most targeted by this type of attack?

Findings point to a broad target set including all employees, finance, HR, legal, executives, and IT helpdesk staff, since document signature requests can plausibly reach any of these roles.

Read the video transcript

There’s a $320-a-month service called NovaCookies that can hijack your Microsoft 365 session, even with MFA turned on. Here’s the trick: you get a real-looking DocuSign envelope, click to review the document, and it bounces you through a Microsoft redirect into a Microsoft 365 login that feels totally normal. But that flow is running through NovaCookies’ adversary-in-the-middle service. When you type your password and approve MFA, they steal your live session token and walk right into your account as you. If you get a DocuSign you weren’t expecting, don’t click the email link, call or message the sender using a saved contact and ask, "Did you actually send this?"

Similar attacks

DocuSign-Themed M365 AiTM Phish Uses Redirect Chain

DocuSign-Themed M365 AiTM Phish Uses Redirect Chain

The recap describes a real Microsoft 365 phishing campaign using DocuSign-themed emails that push victims through multiple redirects to a fake sign-in page. The goal is to steal session tokens (so attackers can log in even if a password changes) and also perform “device code” style sign-in abuse.…

September 7, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Hidden ChatGPT Tasks Leak Data Across Accounts

Hidden ChatGPT Tasks Leak Data Across Accounts

Check Point researchers demonstrated a real proof-of-concept where a victim’s ChatGPT session could be tricked into running hidden, attacker-controlled tasks in parallel with the user’s normal request. In the demo, the attacker used a covert cross-account channel to make ChatGPT access the victim’s…

September 8, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026