NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
A new phishing toolkit called NovaCookies is being used to steal Microsoft 365 sessions by abusing legitimate Docusign notifications and mimicking genuine email shares. Developed by an adversary-in-the-middle (AitM) operation, NovaCookies leverages a fully managed PhaaS model, offering a sophisticated and increasingly accessible way for cybercriminals to conduct large-scale phishing attacks. The kit employs various techniques to evade detection, including cloaking, antibot measures, and a layered approach mimicking legitimate email flows. Several other PhaaS tools, including AnonyMousKIT, p1bot.io, Bluekit, ATHR, ZeroTokens, iAuthFlow V2, LinXcoded, Matrix, ARToken, Blacksite, Balonx Sistema, EvilTokens, Forg365, and DOUBLOON DREDGER, are also actively targeting Microsoft 365 accounts and leveraging similar tactics.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
