NovaCookies Phishing‑as‑a‑Service Hijacks Microsoft 365 Sessions via Spoofed DocuSign Notifications
What Happened – Researchers uncovered a subscription‑based “adversary‑in‑the‑middle” toolkit called NovaCookies. The service sells access to a proxy that intercepts Microsoft 365 sign‑ins, using forged DocuSign notification emails to lure users and capture authenticated sessions.
Why It Matters for Compliance & Audit Readiness
- The attack exploits the same weaknesses SOC 2 Access Control (CC6.1) and Identity Management (CC6.2) are designed to mitigate – unverified login requests and lack of session monitoring.
- Continuous evidence of phishing‑resistance training and MFA enforcement is essential to demonstrate due diligence during a SOC 2 audit.
Who Is Affected – SaaS providers, large enterprises, and any organization that relies on Microsoft 365 for email, collaboration, or document management.
Recommended Actions –
- Enforce MFA and Conditional Access policies for all Microsoft 365 accounts.
- Deploy security‑awareness training that includes real‑world phishing simulations.
- Enable session‑risk analytics and sign‑in anomaly detection in Azure AD.
- Log and retain authentication events for continuous control monitoring.
Source: The Hacker News
Technical Notes – NovaCookies operates as an AitM proxy, leveraging compromised DNS or URL shorteners to redirect legitimate Microsoft 365 login flows. The toolkit is sold for $320/month and uses forged DocuSign notification templates to increase click‑through rates. No specific CVE is associated; the vector is social engineering.