A novel phishing service is giving attackers a turnkey solution to steal authenticated Microsoft 365 sessions for only $320 a month, bypassing multifactor authentication (MFA) protections and highlighting the need for more robust security for enterprise email.
Researchers from enterprise browser maker Island discover the adversary-in-the-middle (AitM) phishing service, dubbed "NovaCookies," which provides lures, domains, hosting, redirects, and support to relay Microsoft 365 logins in real time to steal authenticated sessions, according to a report published today by Shachar Gritzman, a senior security researcher at Island.
NovaCookies — which also includes an option to pay $200 for 14 days — runs like a commercial operation and is targeting hundreds of organizations across multiple regions, with at least 755 domains as part of its dedicated infrastructure. More than half of those organizations are in the US or related to entities in the country, and the infrastructure for the campaign "expanded sharply" from mid-May as it continued to appear through August, Gritzman wrote.
Delivery methods varied across campaigns, but included email messages with genuine Docusign envelopes carrying counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirection hops before reaching the kit. "The initial authentication can succeed normally, without malware, an exploit, or a burst of failed logins, so the sign-in event may look ordinary," Gritzman tells Dark Reading.