A phishing-as-a-service platform called NovaCookies is abusing genuine Docusign notifications to steal Microsoft 365 sessions in real time, according to researchers at Island.
The kit, sold for $320 per month, acts as an adversary-in-the-middle proxy: victims enter passwords and multi-factor authentication codes on pages that relay the authentication to Microsoft while harvesting the resulting session. Organizations hit so far number in the hundreds, spread across the U.S., UAE, Germany, Israel, Canada and the UK.
Observed lures were genuine Docusign envelopes carrying counterfeit document-share notices, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirect hops. The message, document service, and redirect can appear trustworthy until the browser reaches attacker-controlled infrastructure, Island said.
Proofpoint assesses NovaCookies as a variant of the Sneaky 2FA kit, adding dedicated flows for Okta and Entra domains federated to GoDaddy. Unlike Sneaky 2FA, infrastructure is hosted centrally by the PhaaS operator rather than by each affiliate. The platform runs a Cloudflare gate, detects debugging tools, and uses .vu lure domains with alternating-case labels such as Ms36-AcCeSs to impersonate Microsoft services.
One chain exploits the OAuth error-redirect technique Microsoft detailed in March. Island advises defenders that each hop looks legitimate in isolation and the attack only becomes visible as a single event in the browser, so email, identity, and web security teams need to share telemetry.
