'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
A new adversary-in-the-middle (AitM) phishing service called ‘NovaCookies’ is offering a turnkey solution for attackers to steal Microsoft 365 sessions for $320 a month, bypassing MFA protections. The service provides lures, domains, hosting, and redirects to relay logins, and has been operating aggressively since mid-May, targeting hundreds of organizations, with a significant portion located in the US. Unlike traditional phishing-as-a-service, NovaCookies steals authenticated sessions, rendering MFA largely ineffective. Experts recommend a shift in defense strategies, focusing on securing the browser journey and proactively detecting and revoking stolen sessions, rather than relying solely on password resets.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
