NovaCookies: New AiTM Phishing Kit Pilfers Microsoft 365 Sessions for $320/Month
A sophisticated new adversary-in-the-middle (AiTM) phishing toolkit, dubbed **NovaCookies**, is actively targeting hundreds of organizations globally. Offered as a subscription service for $320 per month, this platform facilitates real-time theft of authenticated Microsoft 365 sessions, even bypassing multi-factor authentication (MFA).
Cybersecurity researchers have unveiled details of **NovaCookies**, a potent new adversary-in-the-middle (AiTM) phishing toolkit. This service acts as a proxy to redirect **Microsoft 365** sign-ins, meticulously capturing authenticated sessions in the process.
In a report shared by **Island**, the **NovaCookies** service is characterized as a subscription-based phishing-as-a-service (PhaaS) platform. For $320 a month, affiliates gain access to a platform designed for real-time **Microsoft 365** session theft. The kit has already been leveraged against hundreds of organizations across various sectors in the U.S., U.K., Canada, Germany, Israel, and the U.A.E.
"Observed campaigns used genuine **Docusign** envelopes to carry counterfeit document-share lures, with some clicks routed through legitimate **Microsoft** or **Google** sign-in endpoints as redirect hops before reaching the kit," **Island** stated. "The message, document service and redirect can therefore appear trustworthy until the browser reaches attacker-controlled infrastructure."
Similar to other AiTM phishing kits, **NovaCookies** is engineered to relay **Microsoft 365** authentication through attacker-controlled infrastructure. This allows it to proxy the authentication flow and harvest the resulting session after victims input their passwords and multi-factor authentication (MFA) codes.
Evidence suggests **NovaCookies** is advertised via **Telegram**, which also serves as infrastructure for managing customer profiles, configuring redirect services, and providing support. According to **Proofpoint**, **NovaCookies** is believed to be a variant of the **Sneaky 2FA** phishing kit.
"While the original **Sneaky2FA** appeared to focus mainly on **Microsoft** accounts, the **NovaCookies** variant includes dedicated flows for other identity providers, including **Okta**, and **Entra** domains federated to **GoDaddy**," **Proofpoint** noted in a recent X post.
Crucially, unlike **Sneaky2FA**, **NovaCookies** operates on a fully managed PhaaS model. This means the infrastructure is centrally hosted by the PhaaS operator, alleviating the need for individual affiliates to manage their own hosting.
Many **NovaCookies** lure domains are hosted on the ".vu" domain (e.g., "fordmotbvmorcompany[.]vu"). The phishing URLs often feature alternating-case labels such as PwPt-sHaRe, Ms36-AcCeSs, and ClOd-ViEw, designed to mimic legitimate **Microsoft** services.
One sophisticated attack chain utilizes legitimate **Docusign** notifications as decoys. By leveraging genuine **Docusign** emails, the attacks bypass sender-authentication and reputation checks. The malicious element resides within the shared document itself, rather than the email's direct content.
"Styled as a **Docusign** share notice, it claimed that an accounting department had shared a remittance-advice PDF and invited the recipient to open it," **Island** explained. "The malicious destination sat inside the document, below the layer most mail security products inspect."

The attack then employs an **OAuth** error-redirect technique, previously detailed by **Microsoft** in March, to funnel victims to attacker-controlled infrastructure. The **NovaCookies** phishing infrastructure is a live AiTM relay, designed to capture credentials and session information and relay it to **Microsoft** in real-time.
This commercial offering also incorporates various anti-analysis checks to evade security scanners before serving the fake **Microsoft 365** login form. These include a **Cloudflare** gate and mechanisms to detect execution associated with debugging tools.
"**NovaCookies** is built so each hop can look legitimate on its own: a trusted delivery service, an identity-provider redirect, then a familiar sign-in page," **Island** commented. "Those pieces often land in different tools. The browser is where they become a single event."
This disclosure highlights the continuing proliferation of PhaaS toolkits in the cybercrime underground. These services empower cybercriminals, even those with limited technical expertise, to launch large-scale phishing campaigns. Recent months have seen the emergence of several other notable PhaaS offerings:
* **AnonyMousKIT**: Active since early 2024, this kit uses AI-powered vishing to target owners of stolen devices. It impersonates **Apple Support** to obtain passcodes, **Apple ID**, and 2FA codes on fake domains, ultimately aiming to disable **Activation Lock** for device resale.
* **p1bot.io**: A vishing-as-a-service platform that leverages **ElevenLabs'** text-to-speech capabilities to generate Interactive Voice Response (IVR) prompts in multiple languages, capturing keypad presses (e.g., PINs, OTPs) in real time.
* **Bluekit**: Advertises over 40 website templates, automated domain registration, 2FA support, spoofing, geolocation emulation, and anti-bot cloaking, with add-ons like an AI assistant and voice cloning.
* **ATHR**: Utilizes AI vishing agents, credential harvesting panels, and built-in phishing mailers to scale Telephone-Oriented Attack Delivery (TOAD) attacks.
* **ZeroTokens**: Supports impersonation of 53 financial institution brands to harvest credentials, identity data, payment details, and verification codes, bypassing email security checks using multiple sender domains and **SendGrid** accounts.
* **iAuthFlow V2**: Employs a browser-in-the-middle (BitM) relay to convert a temporary phished **Google** session into persistent access by enrolling an attacker-controlled passkey. It's advertised for $10,000 for the base package, with modules for **Microsoft**, **iCloud**, and **LinkedIn** sold separately.
* **LinXcoded** (aka **Mirage2FA**): Uses compromised senders, analysis evasion, and real-time **Microsoft 365** relays to capture authenticated sessions. Phishing messages originate from compromised **Microsoft 365** tenants and carry the payload as an HTML attachment.
* **Matrix**: Sharing lineage with **Sneaky 2FA**, this kit enables **Microsoft 365** credential-phishing via an AiTM harvester, often employing **OneDrive** notification lures.
* **ARToken**: Steals **Microsoft 365** tokens through the **OAuth** device code flow, facilitating full account takeover via invoice-themed phishing emails from compromised **Google Workspace** or **Microsoft 365** mailboxes linking to anonymous **SharePoint** file shares.