A commercial phishing service called NovaCookies is being marketed as a subscription that can hijack Microsoft 365 sessions even when MFA is enabled. Research describes how it uses legitimate-looking delivery (e.g., real DocuSign envelopes and trusted redirect endpoints) to trick users into completing a real-time sign-in flow that steals their session.
How the Attack Worked
NovaCookies is described as a paid, subscription-style adversary-in-the-middle phishing service built specifically to steal Microsoft 365 sessions, including in environments where MFA is enabled. Rather than trying to guess or brute-force credentials, the service intercepts a real-time sign-in flow. When a target completes what looks like a normal Microsoft 365 login, the attacker captures the resulting session, effectively inheriting access without needing to defeat MFA directly.
The delivery mechanism is designed to look ordinary. Targets receive what appears to be a legitimate DocuSign envelope, a document signature request, which then routes them into a Microsoft 365 sign-in flow. Because the chain uses genuine DocuSign envelopes and trusted Microsoft and Google redirect endpoints, the experience closely mirrors a real, expected business workflow.
Why It Succeeded
The attack's effectiveness comes from combining familiar business processes with technical evasion of MFA protections. Signature requests are routine for many employees, especially in finance, HR, legal, and executive support roles, so an unexpected DocuSign envelope does not automatically stand out as unusual. Layering a real sign-in flow on top of that pretext removes one of the traditional warning signs, an obviously fake login page, since the flow is functionally a real Microsoft 365 authentication.
The operation is also described as industrialized, with rotating infrastructure and an operator dashboard, suggesting a maintained, scalable service rather than a one-off campaign. This kind of infrastructure lets the same techniques be reused across many targets and organizations.
What to Watch For
- An unexpected DocuSign envelope for a document you were not anticipating
- A login flow reached through redirects rather than a normal bookmarked Microsoft 365 login page
- Pressure to sign or review a document quickly without prior context or a related conversation
Building Resistance
Organizations can reduce exposure by encouraging users to verify unexpected signature requests through an independent, known channel, such as calling the sender using a saved phone number rather than replying to the email. Awareness training should also reinforce that MFA does not guarantee protection against session theft: if a user completes a phishing-driven sign-in flow, the resulting session can still be hijacked. Finally, staff across all departments, not just IT, should be trained to treat familiar-looking redirects and trusted-branded links with the same scrutiny as unfamiliar ones, since attackers can and do use legitimate services and redirect endpoints to build credibility.
Key findings
- NovaCookies is described as a paid, subscription-style adversary-in-the-middle (AiTM) phishing service designed to steal Microsoft 365 sessions, including in MFA-enabled environments.
- The delivery chain is designed to look legitimate by using real DocuSign envelopes and trusted Microsoft/Google redirect endpoints.
- The service includes “rotating infrastructure” and “an operator dashboard,” indicating an industrialized, scalable phishing operation.
- Island Security Research published 755 domains as indicators of compromise (IOCs) (not listed in the newsletter text).
Who’s being targeted
- Commonly targeted roles: All employees, Executives, Finance, HR, Legal, IT helpdesk.
- Affected industries: Multiple industries (hundreds of organizations).
- Attack channels: email, website.
- Impersonated: DocuSign (document/signature request) leading into Microsoft 365 login.
Red flags to watch for
- Unexpected DocuSign envelope you weren’t anticipating
- Login flow reached via redirects rather than your normal bookmarked Microsoft 365 login
- Pressure to sign/review a document quickly without context
Frequently asked questions
How does NovaCookies bypass MFA?
It uses an adversary-in-the-middle phishing flow that steals a live Microsoft 365 session after a user completes a real-time sign-in, meaning MFA is satisfied during the attack rather than blocked.
Why do NovaCookies phishing messages look legitimate?
The delivery chain uses real DocuSign envelopes and trusted Microsoft and Google redirect endpoints, making the request appear to come from familiar, expected services.
Does having MFA enabled protect against this attack?
Not fully. Since the attack steals an active session created during a phishing-driven sign-in flow, MFA alone does not prevent account takeover in this scenario.
What roles are most targeted by this type of attack?
Findings point to a broad target set including all employees, finance, HR, legal, executives, and IT helpdesk staff, since document signature requests can plausibly reach any of these roles.
Read the video transcript
There’s a $320-a-month service called NovaCookies that can hijack your Microsoft 365 session, even with MFA turned on. Here’s the trick: you get a real-looking DocuSign envelope, click to review the document, and it bounces you through a Microsoft redirect into a Microsoft 365 login that feels totally normal. But that flow is running through NovaCookies’ adversary-in-the-middle service. When you type your password and approve MFA, they steal your live session token and walk right into your account as you. If you get a DocuSign you weren’t expecting, don’t click the email link, call or message the sender using a saved contact and ask, "Did you actually send this?"