Executive Summary
NovaCookies, a subscription-based phishing platform advertised on Telegram for $320 monthly, has compromised hundreds of organizations across the U.S., U.K., Germany, and U.A.E. by systematically targeting Microsoft 365 sessions. Operating as an Adversary-in-the-Middle proxy, the platform exploits legitimate DocuSign services to deliver counterfeit document-sharing notifications that bypass standard security filters. The attack uses OAuth error-redirect techniques to guide victims through legitimate Microsoft endpoints before routing them to phishing infrastructure, enabling real-time theft of credentials and multi-factor authentication codes.
This incident highlights the evolving sophistication of phishing-as-a-service platforms that leverage trusted cloud services to evade detection, representing a growing trend where threat actors weaponize legitimate business applications to conduct large-scale credential harvesting operations against corporate networks.
Why This Matters Now
The NovaCookies campaign demonstrates how threat actors are increasingly weaponizing trusted cloud services like DocuSign to bypass traditional email security controls, making this a critical concern as organizations rely more heavily on cloud-based collaboration tools.
Attack Path Analysis
Multi-vector campaign involving phishing through DocuSign services leading to session token theft, followed by privilege escalation using vulnerable drivers, lateral movement through compromised networks, C2 establishment via proxy infrastructure, credential and data exfiltration, and potential ransomware deployment targeting critical infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers distributed counterfeit DocuSign notifications containing malicious links that bypassed authentication checks, leading victims through legitimate Microsoft endpoints before routing to NovaCookies phishing infrastructure
Related CVEs
CVE-2026-36425
CVSS 6.5A privilege escalation vulnerability in OPSWAT AppRemover driver (ardrv.sys) allows local attackers to terminate security processes and bypass endpoint protection mechanisms.
Affected Products:
OPSWAT AppRemover Driver – ardrv.sys - vulnerable version
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
Spearphishing Link
Dynamic-link Library Injection
Exploitation for Privilege Escalation
Disable or Modify Tools
Steal Web Session Cookie
Cloud Accounts
Compromise Software Supply Chain
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ID.AM-2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – Third-party Risk Management
Control ID: Article 8
PCI DSS 4.0 – Software Development Security
Control ID: 6.3.2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Web Filtering
Control ID: A.8.23
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-vector campaigns targeting Federal Reserve and cryptocurrency infrastructure expose critical financial networks to state-sponsored espionage and authentication bypass attacks.
Government Administration
State-sponsored actors breached multiple U.S. government agencies including NASA, exploiting IoT botnets and compromised credentials for intelligence collection operations.
Computer Software/Engineering
Supply chain compromises of trusted open-source projects like Trivy and LiteLLM distributed backdoored software updates, potentially affecting thousands of organizations.
Defense/Space
Chinese state-sponsored groups targeted NASA and defense contractors through compromised IoT botnets, enabling espionage traffic masking and sensitive data exfiltration.
Sources
- The Good, the Bad and the Ugly in Cybersecurity – Week 35https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-35-8/Verified
- NovaCookies Phishing Toolkit Analysishttps://island.io/blog/novacookies-phishing-toolkitVerified
- Spark RAT Campaign Targets Cambodian Organizationshttps://www.acronis.com/en-us/blog/spark-rat-cambodia-campaign/Verified
- FBI Disrupts Chinese State-Sponsored QScan and QTRouter Platformshttps://www.fbi.gov/news/press-releases/fbi-disrupts-chinese-hacking-infrastructureVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly reduced the blast radius of this multi-vector campaign by constraining lateral movement across network segments and limiting access to critical infrastructure through identity-aware segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise through phishing would likely still occur, but subsequent access to cloud resources would be constrained through identity-aware access controls and workload isolation policies that limit the scope of compromised credentials.
Control: Zero Trust Segmentation
Mitigation: While local privilege escalation may still occur on compromised endpoints, Zero Trust segmentation would likely limit the scope of elevated access by enforcing identity-based controls that prevent lateral access to sensitive network segments and workloads.
Control: East-West Traffic Security
Mitigation: Lateral movement across network segments would likely be significantly constrained through east-west traffic inspection and segmentation policies that limit cross-segment communication and enforce identity-based access controls between workloads and network zones.
Control: Multicloud Visibility & Control
Mitigation: C2 communication establishment would likely be constrained through comprehensive visibility and control mechanisms that monitor cross-cloud traffic patterns and enforce policy-based restrictions on external communication channels from compromised workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration operations would likely be significantly constrained through egress policy enforcement that monitors and restricts outbound data flows, limiting the volume and scope of sensitive information that could be transmitted to external infrastructure.
While some impact may still occur on initially compromised systems, the scope of cryptocurrency theft and ransomware deployment would likely be significantly reduced due to constrained lateral access and limited reachability to critical financial and operational systems.
Impact at a Glance
Affected Business Functions
- Critical Infrastructure Operations
- Government Services
- Financial Services
- Corporate Authentication Systems
Estimated downtime: 7 days
Estimated loss: $2,500,000
Compromised Microsoft 365 session tokens affecting hundreds of organizations across multiple nations, stolen developer credentials from supply chain attacks, and potential exposure of sensitive government and defense contractor data through state-sponsored intrusions
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with identity-based policies to prevent lateral movement even with compromised credentials
- • Deploy egress security controls with FQDN filtering to block unauthorized data exfiltration and C2 communications
- • Enable multicloud visibility and anomaly detection to identify suspicious automation and repeated malformed requests
- • Enforce encrypted traffic inspection with high-performance encryption for all data in transit
- • Activate inline IPS capabilities to detect and block known exploit patterns and malicious payloads in real-time



