SecurityIndependently confirmed2 publishers3 min readPublished
NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail
Island says the kit relays Microsoft 365 sign-ins behind genuine Docusign envelopes and legitimate Microsoft or Google redirects, leaving sender reputation nothing to grade.
The Watch · Security desk

What happened
- Island published research on NovaCookies, a subscription phishing platform sold at $320 a month that relays Microsoft 365 sign-ins and steals the authenticated session in real time.
- Buyers can also take a short run at $200 for 14 days.
- Lures arrived in genuine Docusign envelopes, with some clicks routed through legitimate Microsoft or Google sign-in endpoints before reaching the kit.
- Hundreds of organisations across the US, UK, Canada, Germany, Israel and the UAE have been targeted so far.
- Proofpoint assesses NovaCookies as a Sneaky 2FA variant, with added flows for Okta and for Entra domains federated to GoDaddy.
Why it matters
- constraint Mail controls tuned to sender authentication and domain reputation are being asked to judge a link they never open, so the decision point has moved inside a document held by a third-party service.
- exposure Tenants that treat MFA as the finish line are reachable, and the duration of the compromise is set by session lifetime rather than by the next password reset.
- cost Under four thousand dollars a year puts a maintained relay in the hands of buyers who could never build one, and the operating cost of that lands on every defender who now faces them.
- contradiction Island's own researcher concedes the kit does not make every buyer capable, which argues against reading the domain count as a count of competent operators.
The Docusign leg of this chain is not a spoof, which is why it works. Island says the notification is a genuine Docusign envelope, so sender-authentication and reputation checks have nothing to fail on, and what is malicious is the document shared through the service [7]. In the case Island describes, the notice claimed an accounting department had shared a remittance-advice PDF, and the malicious destination sat inside the document, below the layer most mail security products inspect [8]. A gateway can grade the sender, the domain and the envelope, be right about all three, and still pass the message.
The second hop does the same thing to identity telemetry, using an OAuth error-redirect technique Microsoft documented in March [16]. The third hop is the one that has to survive automation, and it is built for it: a Cloudflare gate and a check for execution traces associated with debugging tools before the fake Microsoft 365 form is served [9], plus what Island calls short-lived context binding and runtime inspection [10]. The scanner and the employee are not shown the same page. Island's own framing is that each hop looks legitimate alone, the pieces land in different tools, and the browser is where they become one event [25].
Now the money. Annualised, the monthly subscription is $3,840 [23], which buys what Gritzman calls a maintained sign-in flow, infrastructure rotation and an operator interface, work he notes normally requires a specialist to build and keep running [21]. The two-week option costs about $14.29 a day against $10.67 on the monthly plan, roughly a third more per day [24], which is how trials get priced when the seller expects conversion. Telegram carries the advertising and also the management plane: customer profiles, redirect configuration and support [18].
The infrastructure count says where the operator's friction is. At least 755 domains sit in the dedicated infrastructure [14] against hundreds of target organisations [4], more than half of them in the US or tied to US entities [5], meaning the seller burns domains faster than it lands victims [27]. Lure domains cluster on .vu with alternating-case paths such as PwPt-sHaRe and Ms36-AcCeSs [19]. Blocklisting that is a treadmill, not a control.
What is left is detection after the fact, and Gritzman says the initial authentication can succeed normally, without malware, an exploit or a burst of failed logins, so the sign-in event may look ordinary [20]. Material Security's Abhishek Agrawal reads the pivot to session cookies as an answer to passkeys and WebAuthn making credential theft harder [26]. One caveat on the source: Island makes enterprise browsers [13]. The observation about hops converging in the browser holds on its own, but the diagnosis and the product line coincide.
What to watch
- Whether Docusign restricts what shared documents may link to, the only control point in this chain above the mail gateway.
- Whether Proofpoint or Island publish overlap data linking NovaCookies domains to known Sneaky 2FA affiliates, which would show whether the buyer base is new or recycled.
- Whether the Okta and GoDaddy-federated Entra flows appear in observed campaigns rather than only as advertised kit features.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption58
- Hype gap+18
- Incentives74
- Confidence62
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
NovaCookies is an adversary-in-the-middle (AitM) phishing toolkit used as a proxy to redirect Microsoft 365 sign-ins while capturing authenticated sessions.
- [2]
Island characterized NovaCookies, a $320/month service, as a subscription-based phishing platform that facilitates real-time Microsoft 365 session theft.
- [3]
NovaCookies also includes an option to pay $200 for 14 days.
- [4]
The kit has been used to target hundreds of organizations across multiple sectors in the U.S., the U.K., Canada, Germany, Israel and the U.A.E. to date.
- [5]
More than half of the targeted organizations are in the US or related to entities in the country.
- [6]
Observed campaigns used genuine Docusign envelopes to carry counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching the kit.
- [7]
One attack chain bypasses sender-authentication and reputation checks by exploiting the fact that the email is a genuine Docusign notification; what is malicious is the document shared via the service.
- [8]
Island: the lure was styled as a Docusign share notice claiming an accounting department had shared a remittance-advice PDF, and the malicious destination sat inside the document, below the layer most mail security products inspect.
- [9]
The commercial offering includes anti-analysis checks before serving the bogus Microsoft 365 login form, including a Cloudflare gate and a mechanism to detect execution passes associated with debugging tools.
- [10]
According to Island, built-in evasion includes short-lived context binding and runtime inspection to make lures resistant to email scanners.
- [11]
Proofpoint assesses NovaCookies to be a variant of the Sneaky 2FA phishing kit, and says the variant includes dedicated flows for other identity providers, including Okta and Entra domains federated to GoDaddy.
- [12]
Abhishek Agrawal, co-founder and CEO of Material Security, said the kit steals the authenticated session itself, so MFA does not factor in at all, and once the session is captured the attacker is inside the account for as long as that session stays valid, which can be a long time.
- [13]
Island is an enterprise browser maker, and Shachar Gritzman is a senior security researcher there.
- [14]
NovaCookies has at least 755 domains as part of its dedicated infrastructure.
- [15]
Gritzman wrote that the campaign infrastructure expanded sharply from mid-May and continued to appear through August.
- [16]
The attack employs an OAuth error-redirect technique detailed by Microsoft earlier in March to lead victims to attacker-controlled infrastructure.
- [17]
Proofpoint: unlike Sneaky2FA, NovaCookies uses a fully managed phishing-as-a-service model in which affiliates pay to use the platform and infrastructure is hosted centrally by the operator rather than by each affiliate.
- [18]
NovaCookies is advertised via Telegram, which is also used as infrastructure to manage customer profiles, configure redirect services and contact support.
- [19]
Many NovaCookies lure domains are hosted on the .vu domain, with phishing URLs featuring alternating-case labels such as PwPt-sHaRe, Ms36-AcCeSs and ClOd-ViEw.
- [20]
Gritzman told Dark Reading the initial authentication can succeed normally, without malware, an exploit or a burst of failed logins, so the sign-in event may look ordinary.
- [21]
Gritzman wrote that building and maintaining an AitM relay takes specialist work, and that renting one lowers that barrier and gives buyers a maintained sign-in flow, infrastructure rotation and an operator interface.
- [22]
Gritzman said the service lowers the barrier substantially, though it does not make every buyer sophisticated or every campaign successful.
- [23]
The monthly subscription price annualises to $3,840 a year.
- [24]
The 14-day option works out at about $14.29 per day against about $10.67 per day on the monthly plan, roughly 34 percent more per day.
- [25]
Island: NovaCookies is built so each hop can look legitimate on its own, a trusted delivery service, an identity-provider redirect, then a familiar sign-in page; those pieces often land in different tools, and the browser is where they become a single event.
- [26]
Agrawal said the pivot to session theft is likely driven by passkeys and WebAuthn making credential theft harder, and that PhaaS operators are productizing it to meet demand.
- [27]
With at least 755 dedicated domains against hundreds of targeted organizations, the operation registers more domains than it has targets, implying domains are consumed faster than victims are acquired.
Sources
2 independent publishers whose own reporting we read for this story.
- darkreading.com'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
1 article · August 26, 2026
- thehackernews.comNovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Trusted Service Abuse in EmailFollow
- Phishing-resistant authenticationFollow
- Browser cookie and session theftFollow
- Microsoft 365 Identity SecurityFollow
- Phishing-as-a-service kitsFollow
- Adversary-in-the-Middle PhishingFollow