Executive Summary

In August 2026, researchers from Island discovered NovaCookies, a sophisticated adversary-in-the-middle (AitM) phishing-as-a-service platform targeting Microsoft 365 users for $320 per month. The service provides turnkey phishing infrastructure including domains, hosting, and real-time session theft capabilities that bypass multifactor authentication by stealing authenticated session cookies rather than just credentials. NovaCookies targets hundreds of organizations across multiple regions with over 755 dedicated domains, with more than half of targeted organizations located in the US. The platform combines trusted document platforms like DocuSign with legitimate Microsoft redirects and disposable infrastructure to create highly evasive campaigns that appear as ordinary sign-in events.

This incident highlights the evolution of phishing attacks toward session hijacking techniques that render traditional MFA protections ineffective, representing a significant shift in the threat landscape that organizations must address with enhanced browser security and phishing-resistant authentication methods.

Why This Matters Now

The commercialization of session theft through NovaCookies represents a critical escalation in phishing sophistication that makes traditional MFA defenses obsolete, requiring immediate adoption of FIDO-based authentication and zero-trust email security models.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

NovaCookies uses adversary-in-the-middle techniques to steal authenticated session cookies in real-time, allowing attackers to access accounts without needing to bypass MFA since they obtain valid authenticated sessions.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain lateral movement and reduce blast radius through segmented cloud access controls and east-west traffic enforcement, limiting the scope of compromise following successful session hijacking.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial phishing success may still occur, but subsequent cloud resource access would likely be constrained through identity-aware routing and workload-specific access policies that limit the scope of compromised session utilization.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: While session hijacking may succeed, zero trust segmentation would likely restrict the privilege scope and limit access to only explicitly authorized cloud resources and workloads based on identity verification.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between cloud services and workloads would likely be significantly constrained through east-west traffic inspection and microsegmentation policies that limit inter-service communication paths.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control communications would likely be constrained through multicloud traffic visibility and policy enforcement that limits unauthorized outbound connections from compromised cloud workloads and services.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration would likely be constrained through egress policy enforcement that monitors and limits outbound data flows, even when using legitimate API channels with valid authentication credentials.

Impact (Mitigations)

Residual impact would likely be reduced in scope due to segmented access controls, with unauthorized access constrained to specific cloud workloads and services rather than broad organizational resources.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • Document Collaboration
  • Identity Management
  • Data Access Control
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Authenticated Microsoft 365 sessions allowing unauthorized access to corporate emails, documents, contacts, and potentially sensitive business communications across multiple organizations. Over 755 domains compromised with more than half targeting US-based entities.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to limit lateral movement even with stolen sessions
  • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration through legitimate cloud APIs
  • Enable Multicloud Visibility & Control to detect anomalous session patterns and repeated malformed requests across Microsoft 365 services
  • Activate Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on session token abuse
  • Establish Cloud Native Security Fabric (CNSF) controls for real-time inspection and autonomous response to phishing attempts and session hijacking

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image