Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365 lookalike sign-in flow, capturing credentials and MFA codes to hijack sessions.
Key findings
- NovaCookies is described as a subscription phishing platform (~$320/month) designed for real-time Microsoft 365 session theft.
- Campaigns abuse genuine DocuSign notifications/envelopes so the sender and delivery look trustworthy while the malicious link is embedded in the shared document.
- Some clicks are routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching attacker infrastructure.
- The kit functions as an adversary-in-the-middle (AitM) relay that captures passwords, MFA codes, and the resulting authenticated session.
- Observed lure domains include .vu domains and use alternating-case path labels to resemble Microsoft services (e.g., 'PwPt-sHaRe', 'Ms36-AcCeSs', 'ClOd-ViEw').
Who’s being targeted
- Commonly targeted roles: Finance, Accounting, All employees, Executives, Microsoft 365 users.
- Affected industries: Multiple sectors (cross-industry targets), Organizations using Microsoft 365, Organizations using DocuSign.
- Attack channels: email, website.
- Impersonated: DocuSign (genuine notification/envelope), Microsoft 365 sign-in.
Awareness takeaways
- Treat legitimate-platform notifications (e.g., DocuSign) as suspicious when the document content or request is unexpected, attackers can abuse real senders.
- Be cautious of document-share emails that push you to open an attachment/link related to payments (remittance, invoices), especially if you were not expecting it.
- Watch for suspicious redirect chains before login pages; attackers may route clicks through legitimate Microsoft/Google endpoints to make the journey look trustworthy.
- Entering your password and MFA code can still lead to compromise if the site is a real-time proxy, verify the login URL and use trusted bookmarks for Microsoft 365 access.
Red flags to watch for
- Unexpected DocuSign 'share notice' tied to accounting/remittance you weren’t expecting
- After clicking, the browser goes through multiple redirects before landing on a Microsoft 365 sign-in page
- URL/domain does not match your organization’s normal Microsoft 365 login or uses lookalike formatting (e.g., odd casing)
- Sign-in page appears after accessing a document link you didn’t request
- Unusual redirect chain before the sign-in form appears
- Sign-in page is delivered only after passing gates/checks (inconsistent behavior across devices)
Read the video transcript
You get a real DocuSign email: accounting shared a remittance-advice PDF. Looks legit, right? That’s exactly what NovaCookies counts on. Behind that button is NovaCookies, a $320-a-month phishing kit. Your click bounces through real Microsoft or Google sign-in pages, then lands on an attacker-controlled Microsoft 365 login that silently relays your password and MFA in real time. Here’s the trap: every hop looks fine on its own. Real DocuSign sender. Familiar Microsoft redirect. Clean Microsoft 365 sign-in. The only tells are: you weren’t expecting that remittance, the URL isn’t your normal M365 login, and the path looks weird, like 'PwPt-sHaRe' or 'Ms36-AcCeSs'. If you get a DocuSign remittance you weren’t expecting, stop. Don’t sign in from that link. Instead, close it and open Microsoft 365 from your usual bookmark or our portal, then check there.