NovaCookies phishing kit bypasses MFA with live session theft, targeting organizations worldwide

A new phishing-as-a-service platform called NovaCookies has emerged, enabling attackers to steal live Microsoft 365 sessions rather than passwords, raising significant security concerns across multiple countries and prompting calls for more robust authentication measures.

Security researchers have described NovaCookies, a phishing-as-a-service platform that sells for about US$320 a month and is designed to steal live Microsoft 365 sessions rather than passwords. The kit works as an adversary-in-the-middle proxy, relaying the victim’s login in real time and capturing the session cookie after authentication, including when multi-factor prompts are completed. According to reports by Dark Reading and Island, the service has been used against hundreds of organisations across the United States, the United Kingdom, Canada, Germany, Israel and the United Arab Emirates.

The campaigns have used convincing lures built around genuine Docusign envelope notifications, with counterfeit document-sharing links embedded in the message. In some cases, the links first pass through legitimate Microsoft or Google sign-in pages before users are sent to the phishing infrastructure. Researchers say the platform also includes evasive measures such as short-lived context binding and runtime inspection, which make automated email scanning more difficult.

The appeal of the kit is straightforward: it lowers the technical barrier for attackers while bypassing defences that depend on one-time logins and standard MFA prompts. Once a session token is stolen, changing a password or re-enrolling MFA may not immediately remove an attacker’s access, because the token can remain valid until it expires or is explicitly revoked. That makes session theft a different class of risk from traditional credential capture.

For Canadian organisations, the issue is especially relevant because the country is among the confirmed targets and the method exploits a weakness common to many Microsoft 365 deployments. Security teams are being urged to move towards phishing-resistant authentication, including FIDO2 security keys and certificate-based device binding, alongside conditional access rules that check device compliance and location. They should also train staff to treat realistic vendor notifications, not just obvious spoofed pages, as potential phishing routes, and revoke any session showing suspicious reuse rather than waiting for a user to report a problem.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.