
highPhishing
NovaCookies AitM Toolkit Abuses Docusign Notifications to Hijack Microsoft 365 Sessions
Researchers from Island have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies. The toolkit is alleged to abuse genuine Docusign notifications as a delivery mechanism to redirect Microsoft 365 sign-ins and capture authenticated sessions. The service is characterized as a $320/month subscription-based phishing platform. The campaign targets Microsoft 365 users and poses a risk of session hijacking and credential theft.
The Hacker News1 min read