NovaCookies PhaaS Service Bypasses MFA to Steal Microsoft 365 Session Cookies
A phishing-as-a-service platform called NovaCookies is targeting hundreds of organizations by acting as an adversary-in-the-middle proxy between victims and Microsoft 365, stealing authenticated session cookies in real time. The service distributes attack links through legitimate Docusign notifications, fake document-sharing prompts, and compromised websites, routing victims through trusted Microsoft and Google domains before landing on attacker-controlled infrastructure. Victims are presented with convincing Microsoft 365 login and MFA screens, with their credentials and authentication responses silently relayed to real Microsoft servers, allowing attackers to capture valid session cookies post-authentication. Because the login activity can appear as a normal successful sign-in, traditional detection methods focused on login failures or malware execution are largely ineffective, requiring analysis of redirect chains, token anomalies, and post-login behavior. Security researchers recommend adopting phishing-resistant, origin-bound authentication methods such as FIDO2 keys or passkeys, and emphasize that incident response must include revoking active sessions and refresh tokens, not just resetting passwords.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in