THREATOPS
THREAT OPSThreat News › NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

lowthehackernewsPublished 2026-08-26

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process.

In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html