Executive Summary
In August 2026, cybersecurity researchers disclosed the NovaCookies phishing toolkit, a $320/month subscription-based adversary-in-the-middle (AitM) service targeting Microsoft 365 credentials. The campaign exploited genuine DocuSign notifications to deliver counterfeit document-share lures, bypassing email security controls by routing victims through legitimate Microsoft or Google sign-in endpoints before redirecting to attacker-controlled infrastructure. NovaCookies successfully harvested authenticated sessions from hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and U.A.E., capturing both passwords and multi-factor authentication codes in real-time through its proxy-based architecture.
This incident highlights the growing sophistication of phishing-as-a-service platforms that abuse trusted services and legitimate authentication flows to evade detection. The rise of commercial AitM toolkits represents a significant escalation in credential theft capabilities, enabling low-skilled attackers to bypass traditional security controls.
Why This Matters Now
The proliferation of sophisticated phishing-as-a-service platforms like NovaCookies demonstrates how cybercriminals are industrializing credential theft through legitimate service abuse, making traditional email security and MFA protections insufficient against modern adversary-in-the-middle attacks.
Attack Path Analysis
NovaCookies campaigns initiated through genuine DocuSign notifications containing malicious documents that redirected victims to adversary-in-the-middle phishing infrastructure. Attackers captured Microsoft 365 credentials and MFA tokens in real-time, escalated privileges through session hijacking, and potentially moved laterally across federated identity systems. Command and control was maintained through captured authenticated sessions while exfiltrating sensitive organizational data and credentials for further monetization.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers sent genuine DocuSign notifications containing malicious documents with embedded phishing links, using OAuth error-redirect techniques to bypass email security and lead victims to NovaCookies AitM phishing infrastructure
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Steal Web Session Cookie
Multi-Factor Authentication Request Generation
Masquerading: Match Legitimate Name or Location
Phishing: Spearphishing via Service
Impair Defenses: Disable or Modify Tools
Valid Accounts: Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management - Multi-Factor Authentication
Control ID: ID.AM-2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12(a)
Digital Operational Resilience Act (DORA) – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21(2)(a)
PCI DSS 4.0 – Multi-Factor Authentication for All Access
Control ID: 8.4.2
ISO 27001:2022 – Secure Log-on Procedures
Control ID: A.9.4.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
NovaCookies phishing-as-a-service targets Microsoft 365 sessions through genuine Docusign notifications, bypassing MFA and threatening financial institutions' customer authentication systems.
Accounting
Remittance-advice PDF lures specifically target accounting departments, exploiting trust in Docusign workflows to harvest Microsoft 365 credentials and session tokens.
Legal Services
Document-sharing workflows in legal practices face heightened risk from adversary-in-the-middle attacks abusing trusted Docusign notifications for credential harvesting campaigns.
Information Technology/IT
IT organizations managing Microsoft 365 infrastructures must address AitM phishing risks threatening zero trust implementations and east-west traffic security controls.
Sources
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessionshttps://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.htmlVerified
- NovaCookies at Scale: Inside the $320 Phishing Service Targeting Hundreds of Organizationshttps://www.island.io/blog/novacookies-at-scale-inside-the-320-phishing-service-targeting-hundreds-of-organizationsVerified
- Proofpoint Threat Insight on NovaCookies Varianthttps://x.com/threatinsight/status/2072338466076033073Verified
- Microsoft OAuth Redirect Abuse Warninghttps://thehackernews.com/2026/03/microsoft-warns-oauth-redirect-abuse.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this NovaCookies phishing campaign by limiting lateral movement across cloud environments and constraining access to federated identity systems through workload segmentation and east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust architecture could likely limit the scope of initial credential capture by segmenting access to cloud workloads and reducing the number of systems reachable through compromised user sessions
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely constrain the privileges available to hijacked sessions by limiting access to specific workloads and reducing the scope of administrative functions reachable through compromised accounts
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely reduce lateral movement between federated identity systems by enforcing segmentation policies that limit cross-domain access and constrain reachability across cloud service boundaries
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls could likely reduce the persistence of command channels by monitoring cross-cloud communication patterns and limiting unauthorized session activity across federated identity boundaries
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely limit data exfiltration by restricting outbound communication paths and reducing the volume of organizational data accessible through compromised cloud sessions
Remaining impact would likely be limited to data and systems within the compromised user's authorized access scope, with reduced blast radius across organizational cloud environments and constrained downstream account takeover opportunities
Impact at a Glance
Affected Business Functions
- Identity and Access Management
- Email Communications
- Document Management Systems
- Microsoft 365 Productivity Suite
Estimated downtime: 2 days
Estimated loss: $150,000
Microsoft 365 authentication sessions, user credentials, multi-factor authentication codes, and potentially access to corporate email, documents, and cloud-based business applications across hundreds of targeted organizations in multiple sectors including finance, healthcare, manufacturing, and government services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between federated domains and limit blast radius of compromised credentials
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts and connections to known phishing infrastructure
- • Enable Multicloud Visibility & Control to monitor anomalous authentication patterns and detect AitM phishing attempts across identity providers
- • Utilize Threat Detection & Anomaly Response capabilities to establish behavioral baselines and alert on suspicious session patterns and credential usage
- • Implement Cloud Native Security Fabric controls to provide real-time inspection and autonomous response to phishing attempts and session hijacking attacks



