{
  "id": 3835763,
  "title": "NovaCookies: Microsoft 365 AiTM Exploiting Trusted Docusign and Microsoft Redirects",
  "url": "https://urgent.news/2026/08/27/novacookies-microsoft-365-aitm-exploiting-trusted-docusign-and",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-27T22:25:48.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/novacookies-microsoft-365-aitm-exploiting-trusted-docusign-and-microsoft-redirects-36ln"
  },
  "original_language": "en",
  "account": "NovaCookies is a Microsoft 365 AiTM malware that exploits trusted Docusign and Microsoft redirects to steal authenticated session cookies. Users are guided to an AiTM infrastructure through legitimate Docusign notifications and Microsoft/Google redirects, where they enter passwords and MFA responses on fake Microsoft 365 sign-in pages. These credentials are relayed in real time to legitimate Microsoft servers, allowing the thief to acquire authenticated session cookies and reuse them to access the victim's account. The attack starts with links distributed via legitimate Docusign notifications or compromised sites, redirecting users to .vu domain mimicking brand names. The browser's behavior is analyzed to determine if it is a real user, blocking automated analysis. Once inside, the attacker can access the victim's mailbox, files, and cloud applications, and perform various malicious actions. Visibility for victims and administrators is limited, as the attack appears as normal successful logins and requires a combination of browser transitions, redirect paths, device trust states, token anomalies, and post-authentication activities to detect. To mitigate the risk, organizations should use phishing-resistant, origin-bound authentication methods such as passkeys or FIDO2 security keys, and limit credential entries to unknown destinations.",
  "summary": "1. Overview Article Title : NovaCookies at scale: Inside the $320 Phishing Service Targeting Hundreds of Organizations Publisher : Island Publication Date : 2026-08-26 Source : Island Related Sources : Dark Reading , Island Security Research Artifacts Related Malware / Threat Groups / CVEs / Products : NovaCookies service operators and customers, Microsoft 365, Microsoft Entra ID, Docusign,…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}