Skip to main content
Back to Newswire
Security

Researchers detail NovaCookies Microsoft 365 session-theft service

Researchers detail NovaCookies Microsoft 365 session-theft service Image: Primary
Researchers disclosed NovaCookies, a subscription phishing platform that proxies Microsoft 365 sign-ins and captures authenticated sessions after victims submit passwords and multifactor-authentication codes. Island said the $320-per-month service has targeted hundreds of organizations in the United States, United Kingdom, Canada, Germany, Israel and the United Arab Emirates. Observed campaigns used genuine DocuSign notifications carrying counterfeit document-share lures, sometimes passing through legitimate Microsoft or Google sign-in endpoints before reaching attacker-controlled infrastructure. Proofpoint assessed NovaCookies as a Sneaky2FA variant.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire