NovaCookies Phishing Kit Bypasses MFA for $320 a Month
A new subscription-based 'phishing-as-a-service' kit allows low-skill attackers to steal Microsoft 365 session cookies and breach enterprise accounts.
Researchers from Island have uncovered NovaCookies, a subscription-based phishing service that enables attackers to bypass multi-factor authentication (MFA) to breach Microsoft 365 accounts. The service productizes complex session-theft techniques, allowing criminals to maintain unauthorized access to corporate environments for a monthly fee.
For $320 per month, or a short-term rate of $200 for 14 days, NovaCookies provides a turnkey operation for stealing authenticated session cookies. Unlike traditional phishing that targets passwords, this service employs adversary-in-the-middle (AitM) techniques to relay Microsoft 365 logins in real time. By capturing the session cookie after a user has already completed the MFA process, the attacker can enter the account without needing a secondary token.
To deliver these attacks, the service utilized a massive infrastructure of at least 755 dedicated malicious domains, with a significant expansion in activity recorded between mid-May and August. Attackers lured victims using genuine DocuSign envelopes containing counterfeit document-share lures, or by routing victims through legitimate Microsoft and Google sign-in endpoints to mask the destination of the phishing kit.
The Shift to Session Theft
This evolution in phishing tactics is a direct response to the adoption of passkeys and WebAuthn, which have made simple credential theft more difficult. By pivoting to session theft, attackers target the 'authenticated' state of a browser. Once a session cookie is stolen, the system believes the user has already proven their identity, rendering the MFA prompt irrelevant.
Lowering the Barrier to Entry
NovaCookies represents a broader trend of "Phishing-as-a-Service" (PhaaS), which lowers the technical threshold for cybercrime. Shachar Gritzman, a senior security researcher at Island, noted that renting such a service provides buyers with a maintained sign-in flow, infrastructure rotation, and an operator interface, removing the need for the attacker to build their own tools.
Because many organizations rely on MFA as their primary line of defense, this method creates a critical blind spot. Abhishek Agrawal, co-founder and CEO of Material Security, stated that because the kit steals the authenticated session itself, the MFA control most organizations treat as the endgame for phishing does not factor in at all.
The Path Forward
This campaign highlights the insufficiency of traditional perimeter-based email security. Security experts suggest that organizations must move toward phishing-resistant authentication, such as FIDO-based hardware keys, and implement more rigorous session-level monitoring to detect anomalies in how authenticated cookies are used across different devices and locations.