The NovaCookies service is sold as a subscription for $320 per month and, according to researchers, operates as a live adversary-in-the-middle (AitM) relay that captures active Microsoft 365 sessions in real time.
How NovaCookies AitM relay intercepts Microsoft 365 sessions
Cybersecurity teams that examined the toolkit described NovaCookies as a proxy that "relays Microsoft 365 authentication through attacker-controlled infrastructure," allowing operators to harvest authenticated sessions after victims enter credentials and multi-factor authentication (MFA) codes. Island, the researcher who shared the findings with The Hacker News, said the kit is "a subscription-based phishing platform that facilitates real-time Microsoft 365 session theft."
The infrastructure acts as a man-in-the-middle: authentication traffic is proxied through attacker-controlled endpoints and then relayed to Microsoft in real time, while the kit simultaneously captures session tokens, cookies, and one-time codes. The service also includes anti-analysis checks—such as a Cloudflare gate and debugging-tool detection—to try to avoid automated scanners before presenting the bogus Microsoft 365 login form.
Docusign decoy and OAuth error-redirect technique
Operators have used genuine Docusign notifications as the initial decoy. Island observed campaigns that used "genuine Docusign envelopes to carry counterfeit document-share lures," in some cases embedding the malicious destination inside the shared document itself, "below the layer most mail security products inspect." The message appears legitimate until the victim's browser follows the embedded link.
Once clicked, the chain can route through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching attacker-controlled infrastructure. The attack then uses an OAuth error-redirect technique Microsoft described earlier in March to send victims to the AitM relay. Island noted that "each hop can look legitimate on its own: a trusted delivery service, an identity-provider redirect, then a familiar sign-in page."

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageNovaCookies as a managed PhaaS: Telegram, pricing, and lineage
Researchers observed NovaCookies being advertised and managed through Telegram, which operators use both for recruiting customers and for platform operations such as configuring redirects and support. Proofpoint assessed NovaCookies to be a variant of the Sneaky 2FA phishing kit and stressed a shift in operational model: "Unlike Sneaky2FA, NovaCookies uses a fully managed phishing-as-a-service (PhaaS) model where affiliates pay to use a PhaaS platform, and the infrastructure is hosted centrally by the PhaaS operator rather than by each affiliate."
The toolkit employs evasion techniques in its URLs and domains. Many lure domains were registered on the ".vu" top-level domain with alternating-case path labels like PwPt-sHaRe, Ms36-AcCeSs, and ClOd-ViEw—strings designed to masquerade visually as Microsoft services while evading simple detections.
Related PhaaS toolkits and the changing marketplace
NovaCookies is part of a broader PhaaS ecosystem where multiple commercial offerings provide turnkey capabilities for credential theft, device-code phishing, vishing, and cloaking. The report lists several contemporaneous services: AnonyMousKIT (AI-powered vishing targeting stolen Apple devices), p1bot.io (vishing-as-a-service using ElevenLabs TTS), Bluekit (website templates and cloaking), ATHR (AI vishing agents and built-in mailers), ZeroTokens (impersonation of 53 banks), iAuthFlow V2 (browser-in-the-middle relays and passkey enrollment), LinXcoded / Mirage2FA (compromised senders and HTML attachments), Matrix (OneDrive notification lures), ARToken (device-code flow theft via invoice-themed phishing), Blacksite (reverse-proxy AitM paired with Cloaked.gg), Balonx Sistema (Mexican operation with RAT and AI vishing), EvilTokens (device-code kit plus AI analytics), and Forg365 (device code phishing plus AitM and post-compromise mailbox ops).
Some operators are integrating post-capture automation and fraud orchestration: Flare security researcher Assaf Morag said EvilTokens "commoditizes what comes after" capture by automating inbox analysis, stakeholder mapping, and AI-generated fraud messages that convert a captured token into financial compromise.
What this means for technologists and security teams, procurement leaders, and end users
- Technologists and security teams: monitor for redirect chains that include legitimate identity provider endpoints before pointing to unusual ".vu" domains or alternating-case labels; be alert to landing pages that present normal sign-in forms but sit behind Cloudflare gates or anti-analysis checks described in the report.
- Enterprises and procurement leaders: recognize that NovaCookies is sold as a centrally hosted PhaaS at $320/month and managed through Telegram, meaning low technical barriers for affiliates; consider that campaigns have targeted organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E., indicating cross-border exposure.
- End users and mailbox owners: attackers have carried the malicious link inside genuine Docusign shares and in PDFs hosted on platforms such as Notion; Sublime observed actors abusing Notion to present a legitimate sender and infrastructure while embedding overlapping links to increase attack resilience.
The NovaCookies disclosure underscores how commoditized AitM capabilities have become: a packaged relay, managed hosting, Telegram-based operations, and evasion techniques combine to let operators capture sessions even when MFA is in use. Researchers documented the kit's tactics and traced it into a crowded market of service offerings—some focused on voice fraud, others on device code theft—raising practical questions about detection points and who will police the marketplaces where these tools are rented and sold.
Read the full report from The Hacker News: https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html




