Security2 distinct publishers3 min readPublished
Island says the kit relays Microsoft 365 sign-ins behind genuine Docusign envelopes and legitimate Microsoft or Google redirects, leaving sender reputation nothing to grade.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The Docusign leg of this chain is not a spoof, which is why it works. Island says the notification is a genuine Docusign envelope, so sender-authentication and reputation checks have nothing to fail on, and what is malicious is the document shared through the service [9]. In the case Island describes, the notice claimed an accounting department had shared a remittance-advice PDF, and the malicious destination sat inside the document, below the layer most mail security products inspect [10]. A gateway can grade the sender, the domain and the envelope, be right about all three, and still pass the message.
The second hop does the same thing to identity telemetry, using an OAuth error-redirect technique Microsoft documented in March [11]. The third hop is the one that has to survive automation, and it is built for it: a Cloudflare gate and a check for execution traces associated with debugging tools before the fake Microsoft 365 form is served [12], plus what Island calls short-lived context binding and runtime inspection [13]. The scanner and the employee are not shown the same page. Island's own framing is that each hop looks legitimate alone, the pieces land in different tools, and the browser is where they become one event [24].
Now the money. Annualised, the monthly subscription is $3,840 [25], which buys what Gritzman calls a maintained sign-in flow, infrastructure rotation and an operator interface, work he notes normally requires a specialist to build and keep running [19]. The two-week option costs about $14.29 a day against $10.67 on the monthly plan, roughly a third more per day [26], which is how trials get priced when the seller expects conversion. Telegram carries the advertising and also the management plane: customer profiles, redirect configuration and support [16].
The infrastructure count says where the operator's friction is. At least 755 domains sit in the dedicated infrastructure [6] against hundreds of target organisations [4], more than half of them in the US or tied to US entities [5], meaning the seller burns domains faster than it lands victims [27]. Lure domains cluster on .vu with alternating-case paths such as PwPt-sHaRe and Ms36-AcCeSs [17]. Blocklisting that is a treadmill, not a control.
What is left is detection after the fact, and Gritzman says the initial authentication can succeed normally, without malware, an exploit or a burst of failed logins, so the sign-in event may look ordinary [18]. Material Security's Abhishek Agrawal reads the pivot to session cookies as an answer to passkeys and WebAuthn making credential theft harder [22]. One caveat on the source: Island makes enterprise browsers [23]. The observation about hops converging in the browser holds on its own, but the diagnosis and the product line coincide.
Ranked by verification strength, evidence, and original report placement.
NovaCookies is an adversary-in-the-middle (AitM) phishing toolkit used as a proxy to redirect Microsoft 365 sign-ins while capturing authenticated sessions.
Island characterized NovaCookies, a $320/month service, as a subscription-based phishing platform that facilitates real-time Microsoft 365 session theft.
NovaCookies also includes an option to pay $200 for 14 days.
The kit has been used to target hundreds of organizations across multiple sectors in the U.S., the U.K., Canada, Germany, Israel and the U.A.E. to date.
More than half of the targeted organizations are in the US or related to entities in the country.
Observed campaigns used genuine Docusign envelopes to carry counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching the kit.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor telemetry, one independent corroborator, no published indicators
The technical account is specific and internally consistent — named delivery chain, a Microsoft-documented OAuth error-redirect, Cloudflare gating and debugger detection, .vu hosting with alternating-case labels, Telegram administration — and Proofpoint independently places the kit as a Sneaky 2FA variant with additional identity-provider flows. But both articles trace to a single Island report published the same day; the counts (755 domains, hundreds of organizations, more than half US-linked) are unverified by any second party, no indicators or hunting artifacts are published, and no confirmed compromise, victim or affiliate figure appears in either source.
Live campaigns at real scale; buyer base and successful compromises undisclosed
Criminal uptake is evidenced rather than hypothetical: sustained infrastructure growth from mid-May through August, at least 755 dedicated domains, hundreds of organizations targeted across six countries, and a commercial subscription with centralized hosting, Telegram support and tiered pricing — all consistent with paying affiliates. What is missing keeps the score mid-range: no affiliate or customer count, no confirmed session-theft victims, and no post-compromise impact data, so the demand side is inferred from operator behaviour rather than measured.
Mildly overstated: novelty framing outruns the Sneaky 2FA lineage
The underlying activity is real and the mechanics are well described, so the gap is modest rather than large. It is positive because Dark Reading's 'novel'/'turnkey'/'harbinger' framing sits alongside Proofpoint's assessment that this is a variant of an existing kit, because $320 headline pricing invites more inference about the market than two price points support, and because severity rests on interviewed-vendor characterisation with no confirmed compromise disclosed. Island's own caveat that the service 'does not make every buyer sophisticated or every campaign successful' pulls in the opposite direction and keeps the gap small.
Vendor-authored research with prescriptions matching sellers' product lines
Every substantive assessment in the cluster comes from a commercial security seller. The primary research is authored by a senior researcher at Island, an enterprise browser maker, and concludes that the browser is where the attack becomes a single event and that controls belong inside the live browsing session. The main counter-framing comes from the CEO of Material Security, an email-and-data security vendor, who argues perimeter mail filtering is irrelevant and defenses must extend after compromise. A third comment comes from a mobile security vendor. No independent researcher, targeted organization, Microsoft, or Docusign response appears, and only Dark Reading even labels Island's product category.
Consistent same-day reporting on one vendor report, partly corroborated
Two publishers agree on the facts they share, the technical detail is specific enough to be falsifiable, and one external party (Proofpoint) corroborates the kit's existence and lineage. Confidence is held back because the entire evidentiary base is a single vendor report published the same day, all interpretation comes from interested sellers, and no indicators, victim confirmations or third-party telemetry are available to check the scale claims.
security
Vishing gets a product tier: Okta finds kits that steer the victim's browser mid-call1 distinct publisher
security
Mirage2FA: 4,532 domains later, "we have MFA" is not an answer to the auditor1 distinct publisher
leadership
UNC6671 did not retire: four brands, one helpdesk script, and calls to personal phones1 distinct publisher
leadership
The extortion call now comes from your help desk, and the fix is a procedure you own1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026
1 article · August 26, 2026