NovaCookies Phishing Kit Uses Genuine Docusign Notices to Steal Microsoft 365 Sessions
This digest was compiled by AI from multiple sources — links to the originals are below.

Cybersecurity researchers disclosed a new adversary-in-the-middle phishing toolkit called NovaCookies that redirects Microsoft 365 sign-ins and captures authenticated sessions. The $320-per-month subscription service has targeted hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E. Campaigns used genuine Docusign envelopes to carry counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints before reaching the kit.
Key Facts
- NovaCookies is a subscription-based phishing platform priced at $320 per month that facilitates real-time Microsoft 365 session theft.
- The kit has targeted hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E.
- Campaigns used genuine Docusign envelopes to carry counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirect hops.
- Proofpoint assessed NovaCookies as a variant of the Sneaky 2FA phishing kit, with dedicated flows for Okta and Entra domains federated to GoDaddy.
- Many NovaCookies lure domains are hosted on the ".vu" domain, with phishing URLs featuring alternating-case labels such as PwPt-sHaRe, Ms36-AcCeSs, and ClOd-ViEw.
Attack Mechanism
NovaCookies relays Microsoft 365 authentication through attacker-controlled infrastructure, acting as a proxy to harvest the resulting session after victims enter passwords and multi-factor authentication codes. The message, document service, and redirect can appear trustworthy until the browser reaches attacker-controlled infrastructure, according to Island. One attack chain employs Docusign notifications as decoys to lead victims to phishing pages while bypassing sender-authentication and reputation checks because the email is a genuine Docusign notification. The malicious destination sits inside the shared document, below the layer most mail security products inspect.
Distribution and Infrastructure
NovaCookies is advertised via Telegram, with the messaging service also used to manage customer profiles, configure redirect services, and contact support. Unlike Sneaky2FA, NovaCookies uses a fully managed phishing-as-a-service model where affiliates pay to use a centrally hosted platform operated by the PhaaS provider. Many lure domains are hosted on the ".vu" domain, for example "fordmotbvmorcompany[.]vu", with phishing URLs featuring alternating-case labels to masquerade as legitimate Microsoft services.
1 source
NovaCookies Phishing Kit Uses Genuine Docusign Notices to Steal Microsoft 365 Sessions



