NovaCookies Uses Real DocuSign to Steal M365 Sessions

The Hacker News · High sophistication
Last updated August 26, 2026

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365 lookalike sign-in flow, capturing credentials and MFA codes to hijack sessions.

Key findings

  • NovaCookies is described as a subscription phishing platform (~$320/month) designed for real-time Microsoft 365 session theft.
  • Campaigns abuse genuine DocuSign notifications/envelopes so the sender and delivery look trustworthy while the malicious link is embedded in the shared document.
  • Some clicks are routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching attacker infrastructure.
  • The kit functions as an adversary-in-the-middle (AitM) relay that captures passwords, MFA codes, and the resulting authenticated session.
  • Observed lure domains include .vu domains and use alternating-case path labels to resemble Microsoft services (e.g., 'PwPt-sHaRe', 'Ms36-AcCeSs', 'ClOd-ViEw').

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, All employees, Executives, Microsoft 365 users.
  • Affected industries: Multiple sectors (cross-industry targets), Organizations using Microsoft 365, Organizations using DocuSign.
  • Attack channels: email, website.
  • Impersonated: DocuSign (genuine notification/envelope), Microsoft 365 sign-in.

Awareness takeaways

  • Treat legitimate-platform notifications (e.g., DocuSign) as suspicious when the document content or request is unexpected, attackers can abuse real senders.
  • Be cautious of document-share emails that push you to open an attachment/link related to payments (remittance, invoices), especially if you were not expecting it.
  • Watch for suspicious redirect chains before login pages; attackers may route clicks through legitimate Microsoft/Google endpoints to make the journey look trustworthy.
  • Entering your password and MFA code can still lead to compromise if the site is a real-time proxy, verify the login URL and use trusted bookmarks for Microsoft 365 access.

Red flags to watch for

  • Unexpected DocuSign 'share notice' tied to accounting/remittance you weren’t expecting
  • After clicking, the browser goes through multiple redirects before landing on a Microsoft 365 sign-in page
  • URL/domain does not match your organization’s normal Microsoft 365 login or uses lookalike formatting (e.g., odd casing)
  • Sign-in page appears after accessing a document link you didn’t request
  • Unusual redirect chain before the sign-in form appears
  • Sign-in page is delivered only after passing gates/checks (inconsistent behavior across devices)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a real DocuSign email: accounting shared a remittance-advice PDF. Looks legit, right? That’s exactly what NovaCookies counts on. Behind that button is NovaCookies, a $320-a-month phishing kit. Your click bounces through real Microsoft or Google sign-in pages, then lands on an attacker-controlled Microsoft 365 login that silently relays your password and MFA in real time. Here’s the trap: every hop looks fine on its own. Real DocuSign sender. Familiar Microsoft redirect. Clean Microsoft 365 sign-in. The only tells are: you weren’t expecting that remittance, the URL isn’t your normal M365 login, and the path looks weird, like 'PwPt-sHaRe' or 'Ms36-AcCeSs'. If you get a DocuSign remittance you weren’t expecting, stop. Don’t sign in from that link. Instead, close it and open Microsoft 365 from your usual bookmark or our portal, then check there.

Similar attacks

DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026