Phishing-as-a-Service: How NovaCookies Is Targeting Organizations and Eroding Credential Security
Phishing-as-a-Service Operation NovaCookies Targets Hundreds of Organizations Worldwide
A subscription-based phishing service called NovaCookies is actively stealing Microsoft 365 sessions from hundreds of organizations for as little as $320 per month, with nearly half of all targets located in the United States, according to new research from Island.
The findings paint a troubling picture of how cybercrime has evolved into a polished, commoditized industry. Much like a streaming platform offers entertainment on demand, NovaCookies packages sophisticated cyberattack capabilities into an affordable monthly subscription — lowering the barrier for even low-skilled attackers to compromise enterprise-level accounts. The implications for organizations relying on Microsoft 365 are significant and immediate.
How NovaCookies Works
At its core, NovaCookies is a phishing kit built around one goal: stealing authenticated Microsoft 365 sessions in real time. The service intercepts user credentials and multi-factor authentication (MFA) submissions as they happen, capturing the session token before the legitimate user even realizes something is wrong.
This technique, known as adversary-in-the-middle (AiTM) phishing, renders MFA protections largely ineffective. Once an attacker holds a valid session token, they do not need a password or a one-time code — they simply slide into an already-authenticated session undetected. To understand where AiTM fits within the broader landscape of credential-based attacks, it helps to explore the different types of phishing attacks used by modern threat actors and how each exploits distinct weaknesses in user behavior and security infrastructure.
Priced at approximately $320 per month, NovaCookies is an accessible tool for a wide range of malicious actors — not just experienced cybercriminals. Island's research examined artifacts from active NovaCookies campaigns and uncovered hundreds of targeted organizations across multiple industries. The low cost relative to the potential return makes this service particularly alarming for enterprise security teams.
Delivery Methods and Evasion Techniques
Delivery Methods Designed to Deceive
What makes NovaCookies particularly dangerous is the sophistication of its delivery infrastructure. Researchers observed multiple delivery methods used across campaigns, with some of the most convincing leveraging legitimate Docusign envelopes to distribute fraudulent document-share lures.
In these instances, targets received what appeared to be a genuine Docusign notification. Clicks from the embedded links traveled through Microsoft or Google sign-in endpoints before ultimately redirecting users to attacker-controlled infrastructure. Because the initial message and redirect path appear entirely trustworthy, targets have little reason to suspect foul play until it is too late.
This approach is a textbook example of clone phishing tactics that impersonate trusted platforms — where attackers replicate the look, tone, and delivery mechanisms of legitimate services to maximize the credibility of the lure.
Nearly 90% of the phishing lures identified in the research were associated with .vu domains — a country-code top-level domain for the Pacific island nation of Vanuatu. The heavy reliance on .vu domains suggests a deliberate operational choice, likely selected because the domain extension is unfamiliar enough to avoid triggering immediate suspicion while remaining accessible for bulk registration. Security teams should treat .vu domains as a high-priority indicator within email and web filtering systems.
Evasion Techniques That Complicate Detection
NovaCookies does not just steal credentials — it actively resists efforts to detect and analyze it. Island's research found that the service combines several technical mechanisms to frustrate automated security examination:
- Short-lived context binding — limiting the lifespan of phishing sessions to reduce exposure windows
- Proof-of-work challenges — forcing visiting browsers to complete computational tasks that automated scanners typically cannot replicate
- Browser fingerprinting checks — identifying and blocking non-human traffic attempting to analyze the kit
Together, these techniques make it significantly harder for security tools and researchers to dissect NovaCookies campaigns without accessing live infrastructure. Despite these defenses, the lures remain fully functional and reachable to human targets — a deliberate design balance that keeps the service operationally effective while remaining largely invisible to automated defenses.
The Broader Threat and What Organizations Should Do
A Reflection of the Commoditized Cybercrime Ecosystem
United States organizations bore the heaviest share of targeting, accounting for 49.2% of all identified victims. The research did not specify which additional countries or sectors were most affected beyond that figure.
The rise of phishing-as-a-service platforms like NovaCookies reflects a broader and deeply concerning trend in the cybercrime ecosystem. Sophisticated attack capabilities that once required significant technical expertise are now available to virtually anyone willing to pay a monthly fee. For security teams, this means the volume and quality of phishing attempts targeting their organizations is likely to increase simultaneously. The Cybersecurity and Infrastructure Security Agency (CISA) has published guidance on phishing threats that organizations can use to supplement their threat intelligence programs.
Defensive Steps Organizations Should Prioritize
Organizations should treat session token theft as a primary threat model rather than focusing exclusively on password protection. Understanding how social engineering underpins campaigns like NovaCookies is equally critical — learning how to prevent social engineering attacks across your organization provides a strong foundation for reducing susceptibility to lures of this nature.
Beyond awareness, several concrete defensive measures warrant immediate attention:
- Implement phishing-resistant authentication methods, such as FIDO2-based hardware keys, which cannot be intercepted by AiTM proxies
- Monitor for anomalous session activity, particularly session token reuse from unexpected geographic locations or devices
- Train employees to scrutinize document-sharing requests — even those appearing to originate from trusted platforms like Docusign — as a standard part of security awareness programs
- Flag .vu domains as high-risk indicators within email and web filtering systems
- Ensure procurement and finance teams are specifically briefed on document-lure tactics, as they are frequent targets of credential theft campaigns
- Audit Microsoft 365 conditional access policies to ensure that session token reuse from unexpected locations triggers immediate alerts or access blocks
The NovaCookies operation is a clear signal that credential security can no longer rest on MFA alone. As phishing kits grow more capable and more affordable, the onus falls on organizations to layer their defenses, invest in behavioral monitoring, and build a security culture that treats every unsolicited document request — regardless of its apparent source — with appropriate scrutiny.
Source: Security Magazine, August 26, 2026. Research conducted by Island.