www.darkreading.com 8/26/2026, 1:47:13 PM · external

NovaCookies phishing service steals M365 sessions, bypasses MFA

NovaCookies phishing service steals M365 sessions, bypasses MFA
CyberSIXT Evidence Panel
Primary Source island.io

A new phishing service, 'NovaCookies', is being used to steal authenticated Microsoft 365 sessions for $320 a month. This adversary-in-the-middle (AitM) service allows attackers to bypass multifactor authentication (MFA) and offers a turnkey solution that includes lures, domains, hosting, and real-time login relay. Researchers from Island found that NovaCookies targets hundreds of organizations, primarily in the US, using legitimate email messages with fake document-sharing links to conduct attacks.

The service's model simplifies phishing attacks, lowering the required technical skills for attackers. It focuses on stealing session cookies instead of just passwords, effectively bypassing MFA. To defend against such attacks, experts recommend enhancing security measures for enterprise applications and focusing on securing the browser environment.

View Primary Source Via www.darkreading.com

Article by CyberSIXT