highPhishing

NovaCookies AitM Phishing-as-a-Service Toolkit

First seen Aug 27, 2026 · Updated Aug 27, 2026

AitMphishing-as-a-servicesession-hijackingMicrosoft365Docusign-abusecredential-theftagent-relevant

A subscription-based adversary-in-the-middle phishing toolkit called NovaCookies is being used to abuse legitimate Docusign notification emails to lure victims into fraudulent Microsoft 365 login flows. The service acts as a reverse proxy that captures authenticated session cookies, allowing attackers to bypass MFA and hijack active Microsoft 365 sessions for $320/month.

Technical Analysis

NovaCookies operates as an AitM reverse proxy positioned between the victim and Microsoft's legitimate login infrastructure, relaying real-time authentication traffic while capturing session cookies and tokens post-MFA, effectively bypassing traditional multi-factor authentication protections. The campaign leverages genuine Docusign notification emails as an initial access vector, increasing perceived legitimacy and evading email security filters that whitelist known SaaS notification domains. Captured session cookies grant attackers persistent access to Microsoft 365 mailboxes, SharePoint, Teams, and connected OAuth applications without needing the victim's password again. Because Microsoft 365 credentials and OAuth tokens are commonly used by AI agents and automation pipelines (e.g., Copilot integrations, RAG connectors to SharePoint/Exchange, and agent frameworks with M365 API access), compromised sessions could expose agent-accessible data stores, enable unauthorized use of connected AI tools, or allow attackers to pivot into agent orchestration environments that rely on stolen tokens for authentication.

Affected Systems

Microsoft 365 (Exchange Online, SharePoint, Teams, OAuth-integrated applications), organizations using Docusign for e-signature workflows, any environment relying on M365 session-based authentication without session-binding controls

Indicators of Compromise

  • NovaCookies phishing kit infrastructure (specific domains/IPs not disclosed in source)
  • Spoofed/abused Docusign notification emails leading to fraudulent Microsoft 365 login pages
  • Reverse-proxy AitM login portals mimicking login.microsoftonline.com

Remediation Steps

  1. 1

    Enable phishing-resistant MFA

    Deploy FIDO2/WebAuthn hardware keys or certificate-based authentication for Microsoft 365 accounts, which are resistant to AitM session token theft.

  2. 2

    Implement session token binding

    Enable Conditional Access policies with token protection (Continuous Access Evaluation) to bind session tokens to specific devices and detect anomalous reuse.

  3. 3

    Monitor for anomalous sign-ins

    Review Microsoft 365 sign-in logs for impossible travel, unfamiliar IP ranges, or session token reuse from unmanaged devices, and revoke suspicious sessions immediately.

  4. 4

    Educate users on Docusign-themed phishing

    Train employees to verify Docusign links independently and avoid entering Microsoft credentials via embedded notification links.

  5. 5

    Audit OAuth app permissions and agent integrations

    Review and restrict OAuth grants and API scopes tied to AI agents, Copilot, or RAG connectors that use M365 credentials, ensuring least-privilege access and rapid token revocation capability.

Industries Most Exposed

TechnologyFinancial ServicesLegalHealthcareProfessional ServicesAny organization using Microsoft 365 and Docusign

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.