A new phishing-as-a-service platform called NovaCookies enables attackers to harvest Microsoft 365 session tokens for a monthly subscription of just $320, dramatically lowering the technical barrier for conducting adversary-in-the-middle attacks.
NovaCookies operates as a managed phishing service that deploys reverse-proxy infrastructure to intercept user credentials and session cookies. Rather than stealing simple username-password combinations, the toolkit captures authenticated session tokens. These tokens allow attackers to bypass multi-factor authentication protections that would normally block credential reuse from unfamiliar locations or devices.
The service automates attack deployment. Operators lease the platform through a subscription model, receiving a customized phishing page builder, hosting infrastructure, and cookie capture capabilities. Targets receive phishing emails directing them to attacker-controlled login pages that mirror legitimate Microsoft 365 interfaces. When users enter credentials, the reverse-proxy captures both the credentials and the session cookies Microsoft 365 systems issue upon authentication.
Session tokens represent a significant escalation over traditional credential theft. A stolen password can be defeated by multi-factor authentication or by an organization resetting credentials. Session cookies bypass these defenses entirely. Attackers use captured cookies to access victim mailboxes, cloud storage, calendar systems, and other Microsoft 365 services as authenticated users. The attack leaves minimal forensic evidence since legitimate session tokens generate normal audit logs.
The $320 monthly price point targets small and mid-sized criminal operators who lack the technical expertise to build phishing infrastructure from scratch. Previously, conducting AitM attacks required custom coding, reverse-proxy configuration, SSL certificate generation, and hosting management. NovaCookies abstracts these requirements into a point-and-click interface.
Organizations using Microsoft 365 face elevated risk from this service becoming more widespread. Email filtering cannot reliably detect phishing pages hosted on attacker infrastructure since they use legitimate domains and transport layers. The attack succeeds against users who follow standard security training by checking URLs and certificate validity. Attackers respond to CAPTCHA challenges and complete additional verification steps as legitimate users would.
Detection requires behavioral monitoring. Security teams should examine unusual sign-in patterns from unexpected geographic locations or devices, particularly during off-hours. Azure AD sign-in logs and conditional access policies become critical defenses. Enabling passwordless authentication through Windows Hello, FIDO2 keys, or phone sign-in eliminates session tokens as an attack vector since these methods do not generate cookies that phishing can capture.
Incident responders discovering NovaCookies compromise should assume full account takeover occurred. Organizations must force password resets, revoke all active sessions, audit forwarding rules and mailbox delegation, review cloud app consent grants, and assess whether attackers accessed sensitive data or created backdoor accounts.
The emergence of turn-key AitM services reflects broader commoditization of cybercrime. Phishing continues delivering the highest return on investment for attackers. Session token theft eliminates the need for password spraying or credential cracking after initial compromise. Organizations lacking modern authentication controls face substantial exposure if employees receive NovaCookies phishing emails.
