< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-26T19:14:31+05:30

NovaCookies Phishing Kit Exploits Legitimate Docusign Notifications for Microsoft 365 Session Theft

NovaCookies is a phishing-as-a-service (PhaaS) toolkit that leverages legitimate Docusign notifications to redirect users to malicious Microsoft 365 login pages, enabling session theft. The attack employs OAuth error-redirect techniques and anti-analysis measures to bypass security controls.

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process.

In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

Read original article

*** END OF TRANSMISSION ***