NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Summary

A new phishing toolkit named NovaCookies is being used to conduct adversary-in-the-middle (AitM) attacks. These attacks leverage legitimate DocuSign notifications to redirect Microsoft 365 sign-ins and steal authenticated sessions.

IFF Assessment

FOE

This is bad news for defenders as it details a new method used by attackers to compromise user credentials and session tokens for Microsoft 365 accounts.

Defender Context

Defenders should be aware of the NovaCookies toolkit and its tactics, techniques, and procedures, particularly the abuse of legitimate notification services like DocuSign for phishing. It highlights the importance of user education on recognizing sophisticated phishing attempts and the need for robust multi-factor authentication (MFA) and session monitoring solutions to detect and prevent unauthorized access.

Read Full Story →