NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
thehackernews.com Aug 26, 2026

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

AI-summarised brief · reviewed before publication

Cybersecurity researchers revealed NovaCookies, a subscription‑based adversary‑in‑the‑middle phishing toolkit that hijacks Microsoft 365 sign‑ins by relaying authentication through attacker‑controlled servers. The $320‑per‑month service uses genuine DocuSign notifications as lures, routing clicks through legitimate Microsoft or Google sign‑in endpoints before redirecting victims to the kit. NovaCookies, marketed via Telegram, targets hundreds of organizations worldwide, harvesting credentials and MFA codes in real time. The kit’s design mimics trusted services with alternating‑case domain names and anti‑analysis measures.

💡 Why It Matters

  • · The attack demonstrates how phishing‑as‑a‑service platforms can weaponize legitimate email notifications, turning everyday business tools into covert credential‑stealing conduits.
  • · This trend lowers the barrier for large‑scale, sophisticated account‑takeover campaigns.