NovaCookies: Microsoft 365 AiTM Exploiting Trusted Docusign and Microsoft Redirects
1. Overview Article Title : NovaCookies at scale: Inside the $320 Phishing Service Targeting Hundreds of Organizations Publisher : Island Publication Date : 2026-08-26 Source : Island Related Sources : Dark Reading , Island Security Research Artifacts Related Malware / Threat Groups / CVEs / Products : NovaCookies service operators and customers, Microsoft 365, Microsoft Entra ID, Docusign,…
NovaCookies is a Microsoft 365 AiTM malware that exploits trusted Docusign and Microsoft redirects to steal authenticated session cookies. Users are guided to an AiTM infrastructure through legitimate Docusign notifications and Microsoft/Google redirects, where they enter passwords and MFA responses on fake Microsoft 365 sign-in pages.
These credentials are relayed in real time to legitimate Microsoft servers, allowing the thief to acquire authenticated session cookies and reuse them to access the victim's account. The attack starts with links distributed via legitimate Docusign notifications or compromised sites, redirecting users to .vu domain mimicking brand names.
The browser's behavior is analyzed to determine if it is a real user, blocking automated analysis. Once inside, the attacker can access the victim's mailbox, files, and cloud applications, and perform various malicious actions. Visibility for victims and administrators is limited, as the attack appears as normal successful logins and requires a combination of browser transitions, redirect paths, device trust states, token anomalies, and post-authentication activities to detect.
To mitigate the risk, organizations should use phishing-resistant, origin-bound authentication methods such as passkeys or FIDO2 security keys, and limit credential entries to unknown destinations.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.