CyberSecurityBoardThreat Intel · CVEs · Products
Malware

NovaCookies Phishing Kit Abuses Genuine Docusign Notifications to Steal Microsoft 365 Sessions

August 26, 2026

Cybersecurity researchers have disclosed a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies, which is used as a proxy to redirect Microsoft 365 sign-ins while capturing authenticated sessions. The subscription-based service, priced at $320 per month, has been used to target hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E.

According to a report shared by Island, observed campaigns used genuine Docusign envelopes to carry counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirect hops before reaching the kit. The message, document service, and redirect can appear trustworthy until the browser reaches attacker-controlled infrastructure. NovaCookies relays Microsoft 365 authentication through attacker-controlled infrastructure, acting as a proxy to harvest session cookies after victims enter passwords and multi-factor authentication (MFA) codes.

Proofpoint assesses NovaCookies as a variant of the Sneaky 2FA phishing kit, but with dedicated flows for other identity providers, including Okta and Entra domains federated to GoDaddy. Unlike Sneaky2FA, NovaCookies uses a fully managed phishing-as-a-service (PhaaS) model where affiliates pay to use the platform, and infrastructure is hosted centrally by the operator. Many lure domains are hosted on the “.vu” domain, with phishing URLs featuring alternating-case labels to masquerade as legitimate Microsoft services.

The attack chain employs Docusign notifications as decoys, bypassing sender-authentication and reputation checks by leveraging genuine Docusign emails. The malicious destination sits inside the document, below the layer most mail security products inspect. The attack then uses an OAuth error-redirect technique detailed by Microsoft to lead victims to attacker-controlled infrastructure. NovaCookies also includes anti-analysis checks, such as a Cloudflare gate and debugging-tool detection, to evade security scanners.

The disclosure comes as PhaaS toolkits continue to be a lucrative subscription service in the cybercrime underground. Other emerging services include AnonyMousKIT, p1bot.io, Bluekit, ATHR, ZeroTokens, iAuthFlow V2, LinXcoded, Matrix, ARToken, Blacksite, Balonx Sistema, EvilTokens, and Forg365. Additionally, a threat actor tracked as DOUBLOON DREDGER has been observed abusing Notion accounts to host malicious PDFs leading to EvilTokens device code harvesting pages.

CVEs: CVE-2026-58231

Attack groups: DOUBLOON DREDGER

Malware: NovaCookies, Sneaky 2FA, EvilTokens, Tycoon 2FA, AnonyMousKIT, p1bot.io, Bluekit, ATHR, ZeroTokens, iAuthFlow V2, LinXcoded, Matrix

Companies: Island, Proofpoint, Sublime, Flare, Cloudflare, Microsoft, Google, Docusign, Okta, GoDaddy, ElevenLabs

Products: Microsoft 365, Entra, Cloaked.gg, CallFlow, Spyroid