'NovaCookies' Phishing Kit Targets Microsoft 365 Sessions for $320 a Month
AitM-as-a-service lowers the barrier for attackers to steal session cookies and bypass MFA.

Key Takeaways
- NovaCookies is an AitM phishing kit sold for $320 per month, targeting Microsoft 365 sessions.
- The kit steals session cookies, bypassing MFA and enabling persistent account takeover.
- It lowers the barrier to entry for cybercriminals, making sophisticated phishing accessible to less technical actors.
- Organizations should enforce phishing-resistant MFA and monitor for anomalous session behavior.
Related Security News

AI Chatbot Manipulation Campaign Targets Users via Disinformation and Phishing
Security researchers have identified a coordinated campaign in which attackers are manipulating responses from major generative AI platforms, including ChatGPT, Gemini, and Google AI Overview. The operation involves seeding the web with malicious links and data, then optimizing content to influence AI outputs. The goal appears to be amplifying disinformation and directing users to phishing sites designed to harvest credentials.




