Executive Summary

NovaCookies, a subscription-based phishing platform advertised on Telegram for $320 monthly, has compromised hundreds of organizations across the U.S., U.K., Germany, and U.A.E. by systematically targeting Microsoft 365 sessions. Operating as an Adversary-in-the-Middle proxy, the platform exploits legitimate DocuSign services to deliver counterfeit document-sharing notifications that bypass standard security filters. The attack uses OAuth error-redirect techniques to guide victims through legitimate Microsoft endpoints before routing them to phishing infrastructure, enabling real-time theft of credentials and multi-factor authentication codes.

This incident highlights the evolving sophistication of phishing-as-a-service platforms that leverage trusted cloud services to evade detection, representing a growing trend where threat actors weaponize legitimate business applications to conduct large-scale credential harvesting operations against corporate networks.

Why This Matters Now

The NovaCookies campaign demonstrates how threat actors are increasingly weaponizing trusted cloud services like DocuSign to bypass traditional email security controls, making this a critical concern as organizations rely more heavily on cloud-based collaboration tools.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

NovaCookies operates as an adversary-in-the-middle proxy that intercepts and relays MFA codes in real-time to legitimate Microsoft services, effectively stealing authenticated sessions rather than just passwords.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly reduced the blast radius of this multi-vector campaign by constraining lateral movement across network segments and limiting access to critical infrastructure through identity-aware segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise through phishing would likely still occur, but subsequent access to cloud resources would be constrained through identity-aware access controls and workload isolation policies that limit the scope of compromised credentials.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: While local privilege escalation may still occur on compromised endpoints, Zero Trust segmentation would likely limit the scope of elevated access by enforcing identity-based controls that prevent lateral access to sensitive network segments and workloads.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement across network segments would likely be significantly constrained through east-west traffic inspection and segmentation policies that limit cross-segment communication and enforce identity-based access controls between workloads and network zones.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communication establishment would likely be constrained through comprehensive visibility and control mechanisms that monitor cross-cloud traffic patterns and enforce policy-based restrictions on external communication channels from compromised workloads.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration operations would likely be significantly constrained through egress policy enforcement that monitors and restricts outbound data flows, limiting the volume and scope of sensitive information that could be transmitted to external infrastructure.

Impact (Mitigations)

While some impact may still occur on initially compromised systems, the scope of cryptocurrency theft and ransomware deployment would likely be significantly reduced due to constrained lateral access and limited reachability to critical financial and operational systems.

Impact at a Glance

Affected Business Functions

  • Critical Infrastructure Operations
  • Government Services
  • Financial Services
  • Corporate Authentication Systems
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $2,500,000

Data Exposure

Compromised Microsoft 365 session tokens affecting hundreds of organizations across multiple nations, stolen developer credentials from supply chain attacks, and potential exposure of sensitive government and defense contractor data through state-sponsored intrusions

Recommended Actions

  • Implement Zero Trust segmentation with identity-based policies to prevent lateral movement even with compromised credentials
  • Deploy egress security controls with FQDN filtering to block unauthorized data exfiltration and C2 communications
  • Enable multicloud visibility and anomaly detection to identify suspicious automation and repeated malformed requests
  • Enforce encrypted traffic inspection with high-performance encryption for all data in transit
  • Activate inline IPS capabilities to detect and block known exploit patterns and malicious payloads in real-time

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image