NovaCookies Phishing Kit Rents Microsoft 365 Session Theft for $320 a Month
A new subscription phishing service abuses genuine Docusign emails to slip past multi-factor authentication and steal live Microsoft 365 logins.

Key points
- Researchers at Island have disclosed a phishing-as-a-service toolkit called NovaCookies, rented for $320 a month.
- The kit sits between the victim and Microsoft 365, capturing the username, password and authenticated session cookie in transit.
- Attackers route lures through genuine Docusign notification emails, so the messages arrive from a trusted sender and clear standard checks.
- Stealing the session cookie lets criminals sidestep multi-factor authentication, the second-step code or app prompt meant to stop stolen passwords being useful.
- The disclosure extends a pattern Threat Vectr has tracked since June: low-cost, rented phishing platforms built specifically for corporate cloud accounts.
A new phishing kit is being rented to criminals for $320 a month, and its central trick is stealing live Microsoft 365 logins in a way that gets around multi-factor authentication.
The toolkit is called NovaCookies. Researchers at Island described it in a report shared with The Hacker News, calling it a subscription-based phishing platform sold to anyone willing to pay. It's what the industry calls an adversary-in-the-middle kit: when a victim clicks a booby-trapped link, the kit acts as an invisible middleman, showing the real Microsoft 365 login page, forwarding what the victim types to Microsoft, and quietly copying everything as it passes through.
That includes the session cookie, the small piece of data a browser holds after a successful login so the site recognises the user on the next request. Steal the cookie and you inherit the session, no password prompt, no second-factor code required.
How are the phishing emails getting through?
The criminals are sending lures through genuine Docusign notification emails. Because the message really does come from Docusign's own servers, it clears the sender checks that email systems use to spot fakes. The recipient sees a familiar branded email inviting them to view a document; the link inside routes them to the NovaCookies proxy, which mimics a Microsoft 365 sign-in.
This delivery method is new in our coverage of this family of kits. Our Mirage2FA report on 25 August found a similar proxy approach, but that campaign relied on attacker-controlled lure pages rather than a legitimate platform's own notification infrastructure.
Why does this get around multi-factor authentication?
Because the victim really does log in. They enter their password and approve the push notification on their phone. Microsoft, seeing a valid login, issues a session cookie. The middleman kit copies that cookie and hands it to the attacker, who loads it into their own browser and acts as the user.
Multi-factor authentication still blocks a plain stolen password. It doesn't block, on its own, the theft of an already-authenticated session.
Should you worry?
Treat unexpected Docusign emails with the same caution as any other document request, even when the sender address looks legitimate. If you weren't expecting a contract, verify through a phone number or chat channel you already trust, not a reply to the email.
For IT teams, the practical levers are shortening session cookie lifetimes, requiring sign-in from a managed device, and deploying phishing-resistant credentials such as hardware security keys or passkeys. Those methods won't hand a working credential to a proxy site, because the cryptographic handshake is bound to the legitimate domain.
| Detail | What we know |
|---|---|
| Kit name | NovaCookies |
| Price | $320 per month, subscription |
| Target | Microsoft 365 accounts |
| Delivery | Genuine Docusign notification emails |
| Technique | Adversary-in-the-middle proxy, session cookie theft |
What strikes me most here is the delivery vector. Rented proxy kits aren't new; we've covered ten phishing-as-a-service operations in the past 30 days alone. But routing lures through a platform victims already trust, without breaking a single email authentication check, is a meaningful step up. The session is the prize. Getting a legitimate service to carry the bait is how you make sure the victim shows up to hand it over.



