Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

NovaCookies Phishing‑as‑a‑Service Hijacks Microsoft 365 Sessions via Spoofed DocuSign Notifications

Researchers identified NovaCookies, a subscription‑based phishing toolkit that redirects Microsoft 365 sign‑ins using forged DocuSign notifications. The service illustrates why SOC 2 access‑control and security‑awareness controls are critical for audit readiness.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

NovaCookies Phishing‑as‑a‑Service Hijacks Microsoft 365 Sessions via Spoofed DocuSign Notifications

What Happened – Researchers uncovered a subscription‑based “adversary‑in‑the‑middle” toolkit called NovaCookies. The service sells access to a proxy that intercepts Microsoft 365 sign‑ins, using forged DocuSign notification emails to lure users and capture authenticated sessions.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits the same weaknesses SOC 2 Access Control (CC6.1) and Identity Management (CC6.2) are designed to mitigate – unverified login requests and lack of session monitoring.
  • Continuous evidence of phishing‑resistance training and MFA enforcement is essential to demonstrate due diligence during a SOC 2 audit.

Who Is Affected – SaaS providers, large enterprises, and any organization that relies on Microsoft 365 for email, collaboration, or document management.

Recommended Actions –

  • Enforce MFA and Conditional Access policies for all Microsoft 365 accounts.
  • Deploy security‑awareness training that includes real‑world phishing simulations.
  • Enable session‑risk analytics and sign‑in anomaly detection in Azure AD.
  • Log and retain authentication events for continuous control monitoring.

Source: The Hacker News

Technical Notes – NovaCookies operates as an AitM proxy, leveraging compromised DNS or URL shorteners to redirect legitimate Microsoft 365 login flows. The toolkit is sold for $320/month and uses forged DocuSign notification templates to increase click‑through rates. No specific CVE is associated; the vector is social engineering.

📰 Original Source
https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →