NovaCookies Phishing Kit Rents Microsoft 365 Session Theft for $320 a Month
A new subscription phishing service abuses genuine Docusign emails to slip past multi-factor authentication and steal live Microsoft 365 logins.

Key points
- Researchers at Island have disclosed a new phishing-as-a-service toolkit called NovaCookies that sells access for $320 a month.
- The kit sits between the victim and Microsoft 365, capturing usernames, passwords and the authenticated session cookie that normally keeps a user signed in.
- Attackers are sending lures through genuine Docusign notification emails, meaning the messages arrive from a trusted sender and pass standard email checks.
- Stealing the session cookie lets criminals sidestep multi-factor authentication, the second step (a code or app prompt) that is meant to stop stolen passwords being useful.
- The disclosure adds to a growing pattern of low-cost, rented phishing platforms aimed squarely at corporate cloud accounts.
A new phishing kit is being rented out to criminals for $320 a month, and its main trick is stealing live Microsoft 365 logins in a way that gets around multi-factor authentication.
The toolkit is called NovaCookies. Researchers at Island described it in a report shared with The Hacker News, calling it a subscription-based phishing platform sold to anyone willing to pay.
It is what the industry calls an adversary-in-the-middle kit. In plain terms, when a victim clicks a booby-trapped link, the kit acts as an invisible middleman: it shows the real Microsoft 365 login page, forwards what the victim types to Microsoft, and quietly copies everything as it passes through.
That includes the session cookie. A session cookie is the small piece of data your browser holds after you log in successfully, so the site knows it is still you. Steal the cookie and you inherit the login, no password prompt, no second-factor code required.
How are the phishing emails getting through?
The criminals are sending their lures through genuine Docusign notification emails. Because the message really does come from Docusign's own servers, it passes the usual sender checks that email systems rely on to spot fakes.
The recipient sees a familiar branded email inviting them to view a document. The link inside eventually routes them to the NovaCookies proxy page, which mimics a Microsoft 365 sign-in. Everything from that point on looks normal to the victim.
Why does this get around multi-factor authentication?
Because the victim really does log in. They type their password. They approve the push notification on their phone. Microsoft, seeing a valid login, hands back a session cookie. The middleman kit grabs a copy of that cookie and passes it to the attacker, who can then load it into their own browser and act as the user.
Multi-factor authentication still blocks a plain stolen password. What it does not block, on its own, is the theft of an already-authenticated session.
What should ordinary users watch for?
Treat unexpected Docusign emails with the same caution as any other document request, even when the sender address looks right. If you were not expecting a contract, check with the person who supposedly sent it, using a phone number or chat you already trust.
Inside a business, IT teams can reduce the damage by shortening how long session cookies stay valid, by requiring sign-in from a managed device, and by using phishing-resistant sign-in methods such as hardware security keys or passkeys, which will not hand a working credential to a proxy site.
| Detail | What we know |
|---|---|
| Kit name | NovaCookies |
| Price | $320 per month, subscription |
| Target | Microsoft 365 accounts |
| Delivery | Genuine Docusign notification emails |
| Technique | Adversary-in-the-middle proxy, session cookie theft |
Rented phishing kits like this one keep lowering the skill needed to run a convincing attack on a corporate cloud account. The password is no longer the prize. The session is.



