A Look Inside the Phishing Service Attacking Organizations

Research from Island dives into a subscription phishing service known as NovaCookies. For around $320 per month, this service packages real-time Microsoft 365 session theft. The research examined artifacts from the campaign, discovering hundreds of organizations targeted, with nearly 90% associated with lures on .vu domains.
A range of delivery methods were seen in the campaigns. Some observed instances leveraged legitimate Docusign envelopes to send fraudulent document-share lures with clicks traveling through Microsoft or Google sign-in endpoints prior to reaching the kit. Therefore, the message and redirect appears trustworthy until the attacker-controlled infrastructure is reached.
The phishing service then relays Microsoft 365 authentication, enabling it to capture the session following password and MFA submission. By combining short-lived context binding, proof of work and browser checks, it resists automated examination without making the lures unreachable.
This phishing service was predominantly seen targeting United States organizations (49.2%).
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!






