Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Adversary‑in‑the‑Middle Phishing Kit “NovaCookies” Sells Microsoft 365 Session Hijacks for $320 / Month

NovaCookies offers a subscription service that delivers phishing pages capable of stealing active Microsoft 365 session cookies, giving buyers unfettered access to victim accounts. The threat highlights the need for robust MFA, session monitoring, and security‑awareness training to satisfy SOC 2 access‑control requirements.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
darkreading.com

Adversary‑in‑the‑Middle Phishing Kit “NovaCookies” Sells Microsoft 365 Session Hijacks for $320 / Month

What Happened — A new “adversary‑in‑the‑middle” (AitM) phishing‑as‑a‑service called NovaCookies is being marketed on underground forums. For a subscription of $320 per month the kit provides ready‑made phishing pages and automation that capture active Microsoft 365 session cookies, allowing buyers to impersonate legitimate users without needing passwords.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6 (Logical Access) expects organizations to enforce strong authentication and to monitor for anomalous session activity; a service that harvests valid session tokens directly subverts those controls.
  • Continuous‑compliance programs must evidence that phishing awareness training, MFA enforcement, and session‑monitoring logs are in place and regularly reviewed – exactly the controls that mitigate the NovaCookies threat.

Who Is Affected – Enterprises of all sizes that rely on Microsoft 365 for email, collaboration, and file storage; particularly those in technology, professional services, and regulated sectors where SaaS usage is pervasive.

Recommended Actions

  • Verify MFA is enforced for all Microsoft 365 accounts and consider Conditional Access policies that block legacy authentication.
  • Deploy anti‑phishing controls (DMARC, anti‑spoofing, URL rewriting) and run regular Security Awareness Training that includes AitM scenarios.
  • Enable and review Azure AD sign‑in risk and session‑control logs; set up alerts for impossible‑travel and token‑reuse anomalies.

Source: Dark Reading

Technical Notes

  • Attack vector: Phishing pages hosted on attacker‑controlled domains that proxy Microsoft 365 login pages, capturing session cookies after successful credential entry.
  • No public CVE; the service leverages legitimate authentication flows rather than exploiting a software flaw.
  • Data types exposed: Full access to the victim’s Microsoft 365 tenant (email, Teams, SharePoint, OneDrive).

Source: Dark Reading

📰 Original Source
https://www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-month ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →