Skip to content

SecurityIndependently confirmed2 publishers3 min readPublished

NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail

Island says the kit relays Microsoft 365 sign-ins behind genuine Docusign envelopes and legitimate Microsoft or Google redirects, leaving sender reputation nothing to grade.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail
Photo: island.io

What happened

  • Island published research on NovaCookies, a subscription phishing platform sold at $320 a month that relays Microsoft 365 sign-ins and steals the authenticated session in real time.
  • Buyers can also take a short run at $200 for 14 days.
  • Lures arrived in genuine Docusign envelopes, with some clicks routed through legitimate Microsoft or Google sign-in endpoints before reaching the kit.
  • Hundreds of organisations across the US, UK, Canada, Germany, Israel and the UAE have been targeted so far.
  • Proofpoint assesses NovaCookies as a Sneaky 2FA variant, with added flows for Okta and for Entra domains federated to GoDaddy.

Why it matters

  • constraint Mail controls tuned to sender authentication and domain reputation are being asked to judge a link they never open, so the decision point has moved inside a document held by a third-party service.
  • exposure Tenants that treat MFA as the finish line are reachable, and the duration of the compromise is set by session lifetime rather than by the next password reset.
  • cost Under four thousand dollars a year puts a maintained relay in the hands of buyers who could never build one, and the operating cost of that lands on every defender who now faces them.
  • contradiction Island's own researcher concedes the kit does not make every buyer capable, which argues against reading the domain count as a count of competent operators.

The Docusign leg of this chain is not a spoof, which is why it works. Island says the notification is a genuine Docusign envelope, so sender-authentication and reputation checks have nothing to fail on, and what is malicious is the document shared through the service [7]. In the case Island describes, the notice claimed an accounting department had shared a remittance-advice PDF, and the malicious destination sat inside the document, below the layer most mail security products inspect [8]. A gateway can grade the sender, the domain and the envelope, be right about all three, and still pass the message.

The second hop does the same thing to identity telemetry, using an OAuth error-redirect technique Microsoft documented in March [16]. The third hop is the one that has to survive automation, and it is built for it: a Cloudflare gate and a check for execution traces associated with debugging tools before the fake Microsoft 365 form is served [9], plus what Island calls short-lived context binding and runtime inspection [10]. The scanner and the employee are not shown the same page. Island's own framing is that each hop looks legitimate alone, the pieces land in different tools, and the browser is where they become one event [25].

Now the money. Annualised, the monthly subscription is $3,840 [23], which buys what Gritzman calls a maintained sign-in flow, infrastructure rotation and an operator interface, work he notes normally requires a specialist to build and keep running [21]. The two-week option costs about $14.29 a day against $10.67 on the monthly plan, roughly a third more per day [24], which is how trials get priced when the seller expects conversion. Telegram carries the advertising and also the management plane: customer profiles, redirect configuration and support [18].

The infrastructure count says where the operator's friction is. At least 755 domains sit in the dedicated infrastructure [14] against hundreds of target organisations [4], more than half of them in the US or tied to US entities [5], meaning the seller burns domains faster than it lands victims [27]. Lure domains cluster on .vu with alternating-case paths such as PwPt-sHaRe and Ms36-AcCeSs [19]. Blocklisting that is a treadmill, not a control.

What is left is detection after the fact, and Gritzman says the initial authentication can succeed normally, without malware, an exploit or a burst of failed logins, so the sign-in event may look ordinary [20]. Material Security's Abhishek Agrawal reads the pivot to session cookies as an answer to passkeys and WebAuthn making credential theft harder [26]. One caveat on the source: Island makes enterprise browsers [13]. The observation about hops converging in the browser holds on its own, but the diagnosis and the product line coincide.

What to watch

  • Whether Docusign restricts what shared documents may link to, the only control point in this chain above the mail gateway.
  • Whether Proofpoint or Island publish overlap data linking NovaCookies domains to known Sneaky 2FA affiliates, which would show whether the buyer base is new or recycled.
  • Whether the Okta and GoDaddy-federated Entra flows appear in observed campaigns rather than only as advertised kit features.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption58
Hype gap+18
Incentives74
Confidence62
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    NovaCookies is an adversary-in-the-middle (AitM) phishing toolkit used as a proxy to redirect Microsoft 365 sign-ins while capturing authenticated sessions.

  2. [2]

    Island characterized NovaCookies, a $320/month service, as a subscription-based phishing platform that facilitates real-time Microsoft 365 session theft.

  3. [3]

    NovaCookies also includes an option to pay $200 for 14 days.

Sources

2 independent publishers whose own reporting we read for this story.

  1. darkreading.com

    1 article · August 26, 2026

    'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
  2. thehackernews.com

    1 article · August 26, 2026

    NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories