"For around $320 per month, this service packages real-time Microsoft 365 session theft," Island researchers write.
NovaCookies as a subscription service
Research from Island describes NovaCookies as a subscription phishing service sold for roughly $320 per month. The offering is not a one-off toolkit but a commercialized capability that packages real‑time Microsoft 365 session theft. Island's examination of artifacts tied to the campaign showed the service being used against "hundreds of organizations."
Where the lures live: the role of .vu domains
Nearly 90% of the campaign lures identified by Island were associated with .vu domains. That concentration of domain choice stood out in the dataset Island examined and suggests a consistent infrastructure preference across the campaigns the researchers reviewed.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildDelivery methods that look legitimate
Island observed a range of delivery methods. Some campaign instances leveraged legitimate Docusign envelopes to distribute fraudulent document-share lures. In those flows, clicks routed through Microsoft or Google sign‑in endpoints before reaching the attacker-controlled kit, meaning the initial message and redirect could appear trustworthy until the final redirect delivered a victim to hostile infrastructure.
How NovaCookies captures Microsoft 365 sessions
The phishing service relays Microsoft 365 authentication and is able to capture the session after a user submits both their password and multi‑factor authentication (MFA). In other words, the mechanism Island documented does not stop at credential capture; it captures the session itself in real time once authentication steps are completed.
Techniques used to evade automated analysis
Island reports that NovaCookies combines short‑lived context binding, proof‑of‑work challenges, and browser checks to resist automated examination. Those measures are designed to make automated analysis and crawlers less effective while keeping the lures reachable for human victims.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: The capability to relay and capture Microsoft 365 sessions after password and MFA submission changes the attack surface security teams must monitor. Defenders need to consider session‑level telemetry and post‑authentication controls because the threat actor’s objective is a live session, not only static credentials.
- Affected enterprises and procurement leaders: The vendorized, subscription model — priced around $320 per month according to Island — lowers the barrier to entry for acquiring real‑time session theft capabilities. Procurement and risk teams should take the model into account when assessing exposure and may want to track unusual sign‑in patterns originating from domains such as those in the .vu zone.
- End users and the general public: The campaigns observed included apparently legitimate delivery mechanisms, such as Docusign envelopes and flows that pass through Microsoft or Google sign‑in endpoints. That routing can make deceptive messages appear authentic until a victim is redirected to attacker‑controlled infrastructure, increasing the importance of user caution even when the surface looks familiar.
Island's observations point to a pragmatic, commodified threat: a low‑cost subscription that packages the technical means to seize active Microsoft 365 sessions and that leverages delivery methods designed to appear legitimate. The concentration of lures on .vu domains and the fact that 49.2% of observed targets were United States organizations underline the campaign's specific patterns and geographic focus.
The combination of an accessible monthly price, routing through familiar sign‑in endpoints, and session capture after MFA submission raises a simple, consequential question: when real‑time sessions are the prize, how will defenders shift detection and response to stop attackers who are buying turnkey access to authenticated sessions?




