NovaCookies Phishing-as-a-Service Toolkit Targets Microsoft 365 Accounts Through Real-Time Session Theft

Cybersecurity researchers have uncovered a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies, a subscription-based phishing service designed to steal Microsoft 365 credentials and authenticated sessions in real time.

According to research from Island, NovaCookies is offered as a phishing-as-a-service (PhaaS) platform for approximately $320 per month. The service has reportedly been used against hundreds of organizations across the United States, United Kingdom, Canada, Germany, Israel, and the United Arab Emirates.

Unlike conventional phishing pages that simply collect usernames and passwords, NovaCookies acts as a real-time reverse proxy between the victim and Microsoft's legitimate authentication infrastructure. This allows attackers to relay the authentication process while capturing the resulting authenticated session.

NovaCookies Steals Sessions Even When MFA Is Enabled

The primary danger posed by NovaCookies is its ability to intercept authentication sessions after a victim completes the Microsoft 365 login process.

During an AitM attack, the victim is directed to what appears to be a legitimate Microsoft 365 login page. The phishing infrastructure transparently relays authentication requests between the victim and Microsoft.

If the victim enters their password and completes multi-factor authentication (MFA), the attacker can potentially capture the resulting authenticated session information.

This means that simply having MFA enabled does not necessarily prevent an AitM attack.

Once an authenticated session is obtained, attackers can potentially use it to access Microsoft 365 resources without needing to repeat the original authentication process.

NovaCookies Targets Organizations Through Trusted Services

Island researchers observed campaigns in which attackers abused legitimate DocuSign notifications as phishing lures.

Victims received genuine-looking document-sharing messages that appeared to originate from DocuSign. The messages directed recipients toward documents containing malicious destinations.

In one observed campaign, the notification claimed that an accounting department had shared a remittance-advice PDF.

The malicious link was embedded inside the shared document rather than directly in the email body.

This approach can make detection more difficult because the initial email itself may be legitimate.

The attack chain can therefore involve several trusted services:

Legitimate email → DocuSign document → redirect → attacker infrastructure → Microsoft 365 phishing page

Each individual step may appear trustworthy, while the complete chain ultimately leads to credential and session theft.

Attackers Also Abuse Microsoft and Google Redirects

NovaCookies campaigns have also been observed using legitimate Microsoft or Google authentication endpoints as intermediate redirect points.

This technique can help phishing links appear more credible and potentially bypass security controls that inspect only the initial URL.

Island researchers noted that the malicious infrastructure can remain hidden behind several seemingly legitimate stages until the victim's browser reaches the attacker-controlled phishing server.

The final infrastructure operates as a live AitM relay, communicating with Microsoft in real time while capturing authentication information from the victim.

NovaCookies Is Linked to the Sneaky 2FA Family

According to Proofpoint, NovaCookies appears to be a variant of the previously observed Sneaky 2FA phishing kit.

However, NovaCookies expands the targeting capabilities beyond Microsoft accounts.

The toolkit reportedly includes dedicated authentication flows for additional identity providers, including Okta, as well as Entra environments federated through GoDaddy.

Researchers therefore believe the platform represents an evolution of existing AitM phishing infrastructure rather than an entirely unrelated toolkit.

Telegram Used to Operate the Phishing Service

NovaCookies is reportedly advertised through Telegram, which is also used as part of the platform's operational infrastructure.

The messaging platform is used to manage customer profiles, configure redirect services and provide support to customers.

This reflects the increasingly professionalized nature of the cybercrime ecosystem, where attackers can purchase access to ready-made infrastructure rather than developing phishing systems themselves.

NovaCookies follows a fully managed PhaaS model.

Instead of requiring individual affiliates to deploy and maintain their own phishing servers, the infrastructure is centrally hosted and operated by the service provider.

Attackers Use Lookalike Domains

Researchers identified numerous NovaCookies lure domains hosted under the .vu top-level domain.

The phishing URLs also use alternating capitalization patterns designed to make them resemble legitimate Microsoft services.

Examples observed by researchers included strings such as:

  • PwPt-sHaRe
  • Ms36-AcCeSs
  • ClOd-ViEw

These naming conventions are intended to create the visual impression of legitimate Microsoft functionality while directing victims toward attacker-controlled infrastructure.

Anti-Analysis Features Help Hide the Phishing Pages

NovaCookies also incorporates multiple mechanisms designed to make automated analysis more difficult.

Researchers observed the use of:

  • Cloudflare-based filtering
  • Anti-bot mechanisms
  • Browser and execution checks
  • Detection of debugging environments
  • Redirect chains
  • Legitimate-service abuse
  • Dynamic phishing infrastructure

The goal is to prevent security scanners and automated analysis systems from receiving the same malicious content shown to genuine victims.

As a result, automated security tools may encounter a harmless page while a real user receives the Microsoft 365 phishing interface.

NovaCookies Shows the Growing PhaaS Business Model

The discovery highlights the continued growth of phishing-as-a-service, where cybercriminals can subscribe to sophisticated attack infrastructure without needing extensive technical knowledge.

Rather than building phishing pages, authentication proxies and backend systems from scratch, affiliates can purchase ready-to-use platforms.

Several other PhaaS operations have recently demonstrated similar trends.

AnonyMousKIT

AnonyMousKIT has been associated with AI-powered voice phishing campaigns targeting Apple device owners.

Attackers impersonate Apple Support and attempt to obtain sensitive information such as device passcodes, Apple IDs and two-factor authentication codes.

p1bot.io

p1bot.io provides voice-phishing capabilities using text-to-speech technology.

The platform can generate automated voice prompts in multiple languages and capture information entered by victims through telephone keypads.

Bluekit

Bluekit advertises dozens of phishing templates along with features including 2FA support, spoofing, geolocation emulation, anti-bot capabilities and notification systems.

The platform has also promoted AI-related functionality and voice-cloning capabilities.

ATHR

ATHR combines AI-powered voice phishing agents, credential harvesting infrastructure and phishing email functionality to facilitate large-scale telephone-oriented attacks.

ZeroTokens

ZeroTokens focuses on financial organizations and reportedly supports impersonation of dozens of financial brands.

The service is designed to harvest credentials, identity information, payment details and verification codes.

iAuthFlow V2

iAuthFlow V2 uses browser-in-the-middle techniques to obtain authenticated Google sessions and potentially establish persistent access by enrolling attacker-controlled passkeys.

The platform has also been advertised with versions targeting other major services.

LinXcoded / Mirage2FA

LinXcoded, also known as Mirage2FA, uses real-time Microsoft 365 authentication relays, compromised senders and anti-analysis mechanisms.

Its phishing messages can originate from compromised Microsoft 365 tenants and deliver malicious HTML attachments.

Matrix

Matrix is another Microsoft 365 phishing platform linked to the Sneaky 2FA ecosystem.

It uses AitM techniques and has been observed using OneDrive-themed notifications to lure victims toward phishing pages.

ARToken

ARToken uses Microsoft's OAuth device-code authentication flow to steal authentication tokens.

Campaigns can use invoice-themed emails originating from compromised Google Workspace or Microsoft 365 accounts.

Blacksite

Blacksite combines an AitM phishing kit with cloaking infrastructure to prevent automated security systems from analyzing the malicious pages.

It can intercept authentication tokens, session cookies and one-time authentication codes.

Balonx Sistema

Balonx Sistema is a financial phishing operation targeting users of Mexican financial institutions.

The platform combines phishing infrastructure with Android malware and AI-powered voice phishing capabilities.

EvilTokens

EvilTokens provides Microsoft device-code phishing capabilities along with analytics designed to help attackers identify valuable information after compromising accounts.

The platform represents a broader shift toward automating activity that occurs after initial credential theft.

Forg365

Forg365 combines Microsoft device-code phishing, AitM techniques, anti-bot protections, AI-assisted lure generation and post-compromise Microsoft 365 mailbox operations.

DOUBLOON DREDGER Abuses Notion for Token Theft

The NovaCookies disclosure comes alongside observations involving a threat actor tracked as DOUBLOON DREDGER.

Researchers observed the group abusing legitimate Notion accounts to distribute malicious PDF documents.

The PDFs contain links that eventually direct victims toward an EvilTokens device-code phishing page.

The use of Notion provides attackers with several advantages, including:

  • A legitimate email sender
  • Trusted infrastructure
  • A reputable document-hosting platform
  • Reduced suspicion around the initial message

Researchers also observed PDFs containing multiple overlapping links, potentially allowing attackers to maintain campaign availability if one malicious destination is blocked.

The final landing page uses JavaScript obfuscation and encryption techniques designed to make analysis more difficult.

PhaaS Is Lowering the Barrier for Cybercriminals

The emergence of NovaCookies and similar services demonstrates how phishing operations are becoming increasingly commercialized.

Historically, attackers needed technical knowledge to create phishing pages, authentication proxies, redirect infrastructure and command systems.

Modern PhaaS platforms increasingly package these capabilities into subscription services.

This allows less-skilled operators to conduct attacks involving:

  • Credential harvesting
  • MFA interception
  • Session-cookie theft
  • OAuth abuse
  • Device-code phishing
  • Voice phishing
  • AI-generated social engineering
  • Account takeover
  • Post-compromise fraud

The result is a cybercrime ecosystem where sophisticated authentication attacks can be launched without the attacker having to develop the underlying infrastructure themselves.

Key Takeaway

NovaCookies demonstrates why traditional username-and-password security controls are no longer sufficient against modern phishing campaigns.

The toolkit does not simply collect credentials. Its AitM architecture allows attackers to participate in the authentication process in real time and potentially capture authenticated sessions even after victims complete MFA.

The combination of trusted services, redirect abuse, legitimate authentication infrastructure, anti-analysis mechanisms and centralized PhaaS hosting makes these campaigns significantly harder to detect.

For organizations, defenses should therefore extend beyond conventional phishing detection and include strong phishing-resistant authentication, session monitoring, conditional access policies, identity-risk detection and investigation of unusual authentication activity.

The growing PhaaS ecosystem also shows how attackers are increasingly turning advanced phishing and account-takeover techniques into subscription-based services, lowering the technical barrier required to conduct sophisticated identity attacks.