Cyberattackers have found a new way to compromise Microsoft 365 accounts, using a novel phishing service called NovaCookies that steals authenticated sessions for as low as $320 per month. This adversary-in-the-middle (AitM) phishing service has been discovered by researchers at Island, an enterprise browser maker, who warn that it’s giving attackers a turnkey solution to bypass multifactor authentication (MFA) protections and gain access to sensitive information.
NovaCookies is a commercial operation that provides lures, domains, hosting, redirects, and support to relay Microsoft 365 logins in real-time. The service has been observed targeting hundreds of organizations across multiple regions, with over half of the affected companies based in the US or related to entities in the country. The campaign’s infrastructure expanded rapidly from mid-May to August, highlighting the growing threat.
The phishing kit uses tactics familiar to AitM attacks, but what sets it apart is its ability to combine trusted document platforms, legitimate redirects, and disposable infrastructure with real-time Microsoft 365 session theft. This means that attackers can bypass MFA protections and gain access to sensitive information without even needing malware or exploits. The service also includes built-in evasion tactics, such as short-lived context binding and runtime inspection, to help make the lures resistant to email scanners.
The success of attacks facilitated by NovaCookies ultimately depends on the sophistication of the actor, but it’s clear that this phishing kit is lowering the barrier for attackers to create sophisticated campaigns. The fact that session cookies are being stolen rather than just passwords is also a novel aspect of NovaCookies. This pivot is likely driven by an industry that’s made credential theft harder through the use of passkeys and WebAuthn, requiring attackers to find new ways to acquire credentials.
The emergence of NovaCookies serves as a harbinger of things to come, with phishing-as-a-service operators continuing to adapt and improve their methods to meet demand. As one expert notes, “Building and maintaining an adversary-in-the-middle relay takes specialist work, but renting one lowers that barrier and gives buyers a maintained sign-in flow, infrastructure rotation, and an operator interface.” This shift highlights the need for more robust security measures beyond MFA, such as secure authentication protocols.
For organizations using Microsoft 365, this development serves as a reminder to review their security posture and implement additional protection mechanisms. While MFA is still considered a crucial control against phishing attacks, it’s clear that attackers are finding new ways to bypass these protections. By staying informed about emerging threats like NovaCookies and implementing robust security measures, organizations can reduce the risk of falling victim to sophisticated phishing campaigns.
In practical terms, this means that IT teams should be on high alert for suspicious email activity, especially when it comes to legitimate-looking documents or sign-in redirects. It’s also essential to implement additional security controls, such as behavior-based detection and response systems, to help identify and mitigate potential threats. By staying vigilant and adapting to emerging threats, organizations can protect themselves against the growing sophistication of phishing attacks facilitated by services like NovaCookies.
Source: Dark Reading — 2026-08-26