NovaCookies Sells Microsoft 365 Session Theft

Island found NovaCookies, a subscription adversary-in-the-middle phishing service, selling Microsoft 365 session theft for $320 a month and targeting hundreds of organizations across multiple regions. The kit is advertised and managed through Telegram, with a cheaper 14-day option and at least 755 domains in its infrastructure. It works by placing a fake login page between the victim and Microsoft 365, relaying the sign-in in real time and capturing the authenticated session after password and multifactor authentication checks finish. Campaigns have used genuine DocuSign envelopes and document-share lures, with some traffic routed through legitimate Microsoft or Google sign-in endpoints first, so the page trail can look routine until the browser reaches attacker-controlled infrastructure. That makes the compromise live at the session layer, not just the password layer: if a user completes the login flow, the attacker can act as that user without needing the code again. For Microsoft 365 and identity teams, the exposure now sits with any organization that trusts document workflows as a lure path and watches only for failed logins or reused credentials.

Part of the PlainSec briefing for 2026-08-26

Editions

Sources