Executive Summary
In August 2026, researchers from Island discovered NovaCookies, a sophisticated adversary-in-the-middle (AitM) phishing-as-a-service platform targeting Microsoft 365 users for $320 per month. The service provides turnkey phishing infrastructure including domains, hosting, and real-time session theft capabilities that bypass multifactor authentication by stealing authenticated session cookies rather than just credentials. NovaCookies targets hundreds of organizations across multiple regions with over 755 dedicated domains, with more than half of targeted organizations located in the US. The platform combines trusted document platforms like DocuSign with legitimate Microsoft redirects and disposable infrastructure to create highly evasive campaigns that appear as ordinary sign-in events.
This incident highlights the evolution of phishing attacks toward session hijacking techniques that render traditional MFA protections ineffective, representing a significant shift in the threat landscape that organizations must address with enhanced browser security and phishing-resistant authentication methods.
Why This Matters Now
The commercialization of session theft through NovaCookies represents a critical escalation in phishing sophistication that makes traditional MFA defenses obsolete, requiring immediate adoption of FIDO-based authentication and zero-trust email security models.
Attack Path Analysis
NovaCookies phishing-as-a-service leverages adversary-in-the-middle techniques to steal Microsoft 365 sessions through legitimate document platforms and redirects. Attackers relay authentication in real-time to bypass MFA, steal session cookies, and maintain persistent access to compromised accounts for extended periods without triggering traditional security controls.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers use NovaCookies phishing kit with legitimate DocuSign envelopes and Microsoft/Google redirects to deliver AitM phishing pages that intercept M365 authentication flows
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Browser Session Hijacking
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Steal Web Session Cookie
Multi-Factor Authentication Request Generation
Masquerading: Match Legitimate Name or Location
Email Collection: Remote Email Collection
Acquire Infrastructure: Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12(a)
CISA Zero Trust Maturity Model 2.0 – Device Identity and Authentication
Control ID: IA-3
DORA – ICT Risk Management
Control ID: Article 8(4)
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21(2)(a)
PCI DSS 4.0 – Authentication Factor Requirements
Control ID: 8.2.1
ISO 27001:2022 – Password Management System
Control ID: A.9.4.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Microsoft 365 session theft bypassing MFA poses critical risk to financial data, client communications, and regulatory compliance requirements under banking standards.
Health Care / Life Sciences
Phishing-as-a-Service targeting authenticated sessions threatens patient data confidentiality and HIPAA compliance through compromised healthcare communications and records access.
Legal Services
AitM attacks stealing Microsoft 365 sessions compromise attorney-client privilege, confidential case files, and secure communications critical to legal practice operations.
Government Administration
Session cookie theft targeting government Microsoft 365 accounts risks classified information exposure and undermines public sector zero-trust security initiatives.
Sources
- 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Monthhttps://www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-monthVerified
- CISA Phishing Guidancehttps://www.cisa.gov/news-events/news/phishing-guidanceVerified
- Microsoft 365 Security Best Practiceshttps://docs.microsoft.com/en-us/microsoft-365/security/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain lateral movement and reduce blast radius through segmented cloud access controls and east-west traffic enforcement, limiting the scope of compromise following successful session hijacking.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial phishing success may still occur, but subsequent cloud resource access would likely be constrained through identity-aware routing and workload-specific access policies that limit the scope of compromised session utilization.
Control: Zero Trust Segmentation
Mitigation: While session hijacking may succeed, zero trust segmentation would likely restrict the privilege scope and limit access to only explicitly authorized cloud resources and workloads based on identity verification.
Control: East-West Traffic Security
Mitigation: Lateral movement between cloud services and workloads would likely be significantly constrained through east-west traffic inspection and microsegmentation policies that limit inter-service communication paths.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely be constrained through multicloud traffic visibility and policy enforcement that limits unauthorized outbound connections from compromised cloud workloads and services.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration would likely be constrained through egress policy enforcement that monitors and limits outbound data flows, even when using legitimate API channels with valid authentication credentials.
Residual impact would likely be reduced in scope due to segmented access controls, with unauthorized access constrained to specific cloud workloads and services rather than broad organizational resources.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Collaboration
- Identity Management
- Data Access Control
Estimated downtime: 3 days
Estimated loss: N/A
Authenticated Microsoft 365 sessions allowing unauthorized access to corporate emails, documents, contacts, and potentially sensitive business communications across multiple organizations. Over 755 domains compromised with more than half targeting US-based entities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to limit lateral movement even with stolen sessions
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration through legitimate cloud APIs
- • Enable Multicloud Visibility & Control to detect anomalous session patterns and repeated malformed requests across Microsoft 365 services
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on session token abuse
- • Establish Cloud Native Security Fabric (CNSF) controls for real-time inspection and autonomous response to phishing attempts and session hijacking



