Back to all lessons
Awareness Lessons
2 months ago

NovaCookies PhaaS Hijacks Docusign Lures to Bypass MFA and Steal M365 Sessions

The NovaCookies campaign exploits user trust in legitimate Docusign email notifications to lure victims into an adversary-in-the-middle (AiTM) phishing flow that captures both credentials and live MFA tokens, effectively rendering standard multi-factor authentication insufficient on its own. The attack abuses the perceived legitimacy of a well-known SaaS platform to bypass user suspicion, highlighting how threat actors increasingly weaponize trusted brand notifications rather than crafting obviously fake emails. Once a session cookie is stolen, attackers gain persistent, authenticated access to Microsoft 365 environments without needing to re-authenticate. This matters because session hijacking sidesteps even strong MFA implementations, meaning organizations relying solely on MFA as their last line of defense are still exposed to full account takeover.

Tactical Insight

Immediate actions

  • Deploy phishing-resistant MFA methods (FIDO2/passkeys) that bind authentication to the legitimate origin domain, preventing AiTM token theft.
  • Enable Microsoft 365 Conditional Access policies to restrict sessions by device compliance, location, and require continuous access evaluation (CAE) to invalidate stolen tokens rapidly.
  • Warn users to verify unexpected Docusign notification links by navigating directly to the Docusign portal rather than clicking embedded URLs.

Detection measures

  • Configure Microsoft Sentinel or Defender for Cloud Apps alerts on impossible-travel sign-ins, new country logins, and token replay anomalies indicative of session hijacking.
  • Monitor for suspicious OAuth token grants and unfamiliar registered applications appearing in the M365 tenant after any suspicious login event.
  • Establish threat intelligence feeds that track phishing-as-a-service (PhaaS) kits advertised on Telegram and dark web forums to proactively block associated infrastructure.

Long-term improvements

  • Implement a Zero Trust architecture with short-lived session tokens and strict re-authentication requirements for sensitive actions such as email forwarding rule changes or MFA method updates.
  • Conduct regular security awareness training simulating AiTM and brand-impersonation phishing scenarios so employees recognize trust-abuse tactics.
  • Establish an email link isolation or rewriting policy (via a Secure Email Gateway) to defang redirector chains before they reach end users.