NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

A sophisticated cyber campaign, dubbed “NovaCookies,” has been uncovered, leveraging genuine DocuSign notifications to steal Microsoft 365 session credentials. The attacks, which have been ongoing for months, target organizations with a high volume of DocuSign usage, allowing hackers to phish employees and gain unauthorized access to sensitive data.

At the heart of the NovaCookies campaign is a clever social engineering tactic, where attackers exploit the trust built between employees and legitimate services like DocuSign. By hijacking genuine notifications, which often contain sensitive information, hackers create an illusion of legitimacy, convincing victims to click on malicious links or download malware-laced attachments. This ploy relies on the fact that many organizations use DocuSign for high-priority tasks, making it more likely that employees will engage with these notifications in a rush.

The campaign’s reach is substantial, affecting numerous companies worldwide, including those in the financial and healthcare sectors. According to researchers, NovaCookies has been able to bypass some security measures by using compromised accounts to send notifications from within an organization’s own DocuSign instance. This makes it challenging for defenders to detect and prevent these attacks without advanced threat intelligence.

One of the most striking aspects of this campaign is its ability to exploit an often-overlooked vulnerability: cross-domain privilege escalation. In essence, hackers use legitimate services as stepping stones to elevate their privileges within a target organization’s infrastructure. This allows them to move laterally across different systems and steal sensitive data without triggering traditional security alarms.

The NovaCookies campaign serves as a stark reminder of the importance of user awareness in preventing social engineering attacks. With more sophisticated tactics emerging, it is essential for employees to be cautious when interacting with notifications, even if they appear legitimate. Furthermore, organizations must re-evaluate their security posture and consider implementing advanced threat detection tools that can identify and block suspicious activity related to cross-domain privilege escalation.

In light of this campaign, we urge all users to exercise extreme caution when dealing with notifications from services like DocuSign. Always verify the authenticity of such messages by contacting the relevant department or service provider directly. Additionally, organizations should consider implementing two-factor authentication for sensitive applications and investing in advanced threat detection solutions that can identify sophisticated attacks like NovaCookies.


Source: The Hacker News — 2026-08-26