NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

A sophisticated cyber campaign, dubbed NovaCookies, has been exploiting genuine DocuSign notifications to hijack Microsoft 365 sessions and steal sensitive user data. The attack’s clever use of phishing tactics and exploitation of legitimate authentication mechanisms has left security experts sounding alarm bells.

At its core, the NovaCookies campaign relies on social engineering, where attackers send malicious emails that appear to be from a trusted source – in this case, DocuSign. The email contains a link or attachment that, when clicked or opened, installs malware on the victim’s device. This malware then intercepts authentication cookies for Microsoft 365 services, allowing the attacker to gain unauthorized access to user sessions and sensitive data.

The attack is particularly insidious because it leverages genuine notifications from DocuSign, which are often used to facilitate electronic signatures and document sharing in a work environment. Attackers likely obtained or spoofed these notification templates to make their malicious emails appear legitimate. Once the malware is installed on a device, it can monitor and capture authentication cookies for Microsoft 365 services, effectively allowing attackers to assume the victim’s identity.

What makes this attack particularly concerning is its ability to bypass traditional security measures. Since the attackers are using genuine notifications from a trusted source, many security software solutions may not flag these emails as malicious. Furthermore, because the malware targets Microsoft 365 sessions specifically, it can exploit existing privileges and access levels that users have within their organization.

As with any sophisticated attack, the NovaCookies campaign is likely designed to evade detection by traditional security measures. This highlights the importance of user education in preventing such attacks. Employees must be vigilant when receiving emails or notifications from unfamiliar sources, especially those related to sensitive work-related tasks like electronic signatures. Moreover, organizations should implement additional security measures, such as multi-factor authentication and session monitoring, to prevent unauthorized access to Microsoft 365 services.

Ultimately, the NovaCookies campaign serves as a stark reminder of the importance of staying one step ahead of attackers in today’s threat landscape. By understanding how attacks work and taking proactive steps to secure our digital lives, we can reduce the risk of falling victim to such sophisticated campaigns.


Source: The Hacker News — 2026-08-26