**Phishing Service Offers Turnkey Solution to Steal Microsoft 365 Sessions for $320 a Month**
A novel phishing service has emerged, offering a commercial-grade solution for attackers to steal authenticated Microsoft 365 sessions for as little as $320 a month. Dubbed “NovaCookies,” this adversary-in-the-middle (AitM) phishing service is targeting hundreds of organizations across multiple regions, with at least 755 domains as part of its dedicated infrastructure.
According to researchers from Island, the enterprise browser maker that discovered NovaCookies, the service provides lures, domains, hosting, redirects, and support to relay Microsoft 365 logins in real-time. This allows attackers to bypass multifactor authentication (MFA) protections and gain unauthorized access to sensitive data. The service also includes built-in evasion tactics, such as short-lived context binding and runtime inspection, making the lures resistant to email scanners.
NovaCookies runs like a commercial operation, with options for attackers to pay $320 per month or $200 for 14 days. The infrastructure behind the campaign has expanded sharply since mid-May, with at least half of the targeted organizations based in the US or related to entities in the country.
The success of attacks facilitated by NovaCookies depends on the sophistication of the attacker. While the service lowers the barrier to entry for phishing attacks, it does not guarantee success for every buyer. However, its pivot to stealing session cookies rather than just passwords is a significant concern for organizations that rely on MFA as their primary security measure.
“The initial authentication can succeed normally, without malware, an exploit, or a burst of failed logins, so the sign-in event may look ordinary,” said Shachar Gritzman, senior security researcher at Island. “This means that even with MFA in place, attackers can still gain unauthorized access to sensitive data.”
The emergence of NovaCookies highlights the need for organizations to move beyond traditional MFA solutions and adopt more robust authentication methods. This includes using passkeys and WebAuthn, which require a stronger form of verification than traditional passwords.
As Abhishek Agrawal, co-founder and CEO of Material Security, noted: “Session theft is a new way for attackers to bypass security measures. It’s not surprising to see phishing-as-a-service operators productize it to meet demand.”
To mitigate the risk of session cookie theft, organizations should consider implementing additional security measures beyond MFA. This includes:
* Regularly monitoring user activity and detecting suspicious behavior
* Implementing advanced threat detection solutions that can identify potential security threats
* Educating users on the risks associated with phishing attacks and how to spot suspicious emails
* Conducting regular security audits to identify vulnerabilities in their systems
By taking these steps, organizations can reduce the risk of session cookie theft and protect sensitive data from unauthorized access.
Source: Dark Reading — 2026-08-26