Adversary‑in‑the‑Middle Phishing Kit “NovaCookies” Sells Microsoft 365 Session Hijacks for $320 / Month
What Happened — A new “adversary‑in‑the‑middle” (AitM) phishing‑as‑a‑service called NovaCookies is being marketed on underground forums. For a subscription of $320 per month the kit provides ready‑made phishing pages and automation that capture active Microsoft 365 session cookies, allowing buyers to impersonate legitimate users without needing passwords.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6 (Logical Access) expects organizations to enforce strong authentication and to monitor for anomalous session activity; a service that harvests valid session tokens directly subverts those controls.
- Continuous‑compliance programs must evidence that phishing awareness training, MFA enforcement, and session‑monitoring logs are in place and regularly reviewed – exactly the controls that mitigate the NovaCookies threat.
Who Is Affected – Enterprises of all sizes that rely on Microsoft 365 for email, collaboration, and file storage; particularly those in technology, professional services, and regulated sectors where SaaS usage is pervasive.
Recommended Actions
- Verify MFA is enforced for all Microsoft 365 accounts and consider Conditional Access policies that block legacy authentication.
- Deploy anti‑phishing controls (DMARC, anti‑spoofing, URL rewriting) and run regular Security Awareness Training that includes AitM scenarios.
- Enable and review Azure AD sign‑in risk and session‑control logs; set up alerts for impossible‑travel and token‑reuse anomalies.
Source: Dark Reading
Technical Notes
- Attack vector: Phishing pages hosted on attacker‑controlled domains that proxy Microsoft 365 login pages, capturing session cookies after successful credential entry.
- No public CVE; the service leverages legitimate authentication flows rather than exploiting a software flaw.
- Data types exposed: Full access to the victim’s Microsoft 365 tenant (email, Teams, SharePoint, OneDrive).
Source: Dark Reading