Picture the last time you signed into Microsoft 365. You typed your password. Your phone buzzed with a code, or you tapped approve on the authenticator app. The page loaded. You were in. That whole sequence is the thing most of us treat as proof that we are safe. You proved who you were, the system let you in, done.
Now imagine every keystroke and every code in that sequence quietly passing through a stranger before it reached Microsoft. You still got in. So did they.
That is the short version of a new phishing toolkit that researchers have been tracking, and it is worth understanding because it breaks the mental model a lot of teams still rely on.
What NovaCookies actually is
Security researchers recently disclosed details of an adversary-in-the-middle phishing kit called NovaCookies. According to The Hacker News, which received the research from the security firm Island ahead of publication, NovaCookies is sold as a subscription service, roughly $320 a month, that operates as a proxy to redirect Microsoft 365 sign-ins and capture authenticated sessions along the way.
Adversary-in-the-middle, usually shortened to AitM, is the mechanism that makes this dangerous. A traditional phishing page just collects your password on a fake screen, then the attacker tries to reuse it later. That approach falls apart the moment multi-factor authentication is in the picture, because the attacker does not have your second factor.
AitM solves that problem for the attacker. Instead of a static fake page, the phishing site sits between you and the real Microsoft login as a live relay. You land on a page that looks like the genuine sign-in. When you enter your password, the kit passes it to Microsoft in real time. When Microsoft asks for your MFA code, that request flows back to you. You approve it, because from where you are standing everything looks normal. The kit relays your approval to Microsoft, and Microsoft hands back a valid session token, the small piece of data that tells your browser you are already logged in.
The kit grabs that token. From that point the attacker does not need your password or your MFA at all. They have the session itself, and they can ride it into your mailbox, your files, and anything else that account touches.
The subscription model is the part that should get attention. At $320 a month, this is not a bespoke tool built by an elite crew for a single target. It is a product. Someone with modest skills can rent it, point it at your industry, and run campaigns. That lowers the bar for who can pull off an attack that used to require real technical chops.
Why this matters for your business
Here is the uncomfortable part. If your security posture rests mainly on “we have MFA turned on,” NovaCookies is built specifically to walk past that.
MFA is still worth having. It stops a huge volume of low-effort attacks cold, and turning it off would be a mistake. But MFA verifies that the right person logged in at the moment of login. It does not keep watching after the session token is issued. Session-theft kits like this one target exactly that gap, the window after you have proven who you are, when the token is doing the trusting on your behalf.
For a small or mid-sized business, the practical risk plays out fast. A stolen Microsoft 365 session usually means access to email first. From there an attacker reads message history to learn how your company talks, then sends invoice-change requests or wire instructions from a real internal account, which is far more convincing than any spoofed address. They set inbox rules to hide their own replies. They reach into SharePoint and OneDrive for contracts and financial records. None of it trips an alarm, because as far as the system is concerned, a legitimate authenticated user is doing legitimate work.
The reason this class of attack keeps working is not that companies are careless. It is that the login moment feels like the finish line, and most defenses are built around that moment. The attackers moved past it.
What to do now
You do not need to panic, and you do not need to rip anything out. You need to close the gap after login, not just at login.
-
Keep MFA on, and move toward phishing-resistant methods. Standard app-approval and code-based MFA can be relayed by an AitM kit. Phishing-resistant options, FIDO2 security keys and passkeys, bind the credential to the real site. CISA calls FIDO and WebAuthn the only widely available phishing-resistant authentication, and says the FIDO protocol will block the attempt when a user is tricked into logging into a fake website. Prioritize these for admins and finance staff first.
-
Turn on conditional access policies in Microsoft 365. These let you require that sign-ins come from managed, compliant devices or known locations. A relayed session coming through an attacker’s proxy will often fail those conditions even when the password and MFA check out.
-
Shorten session lifetimes for sensitive accounts and enforce re-authentication. A stolen token is only useful while it is valid. Tighter session policies shrink the attacker’s window.
-
Watch for the signs of a hijacked session, not just a failed login. Impossible-travel sign-ins, new inbox forwarding rules, and unfamiliar OAuth app grants are the fingerprints of session abuse. Someone or something has to be looking for them.
-
Train your team on the one detail that gives these pages away. AitM sites still have to live at a URL that is not Microsoft’s. Slow down and check the address bar before entering credentials, especially on a login prompt that arrived by email.
The hard truth is that “we have MFA” is no longer a complete answer. It is a good first layer that now needs layers behind it, watching what happens after the door opens.
Common Questions
Does MFA still work against NovaCookies? MFA still blocks most everyday attacks and should stay on. What it does not do is stop an adversary-in-the-middle kit that relays your login in real time and steals the session token afterward. Phishing-resistant MFA, meaning security keys or passkeys, is the version built to resist this specific technique.
How would I even know if a session was stolen? You usually will not see it at the login screen, because the login looked legitimate. The signs show up afterward: sign-ins from unexpected locations, new mail-forwarding or inbox rules you did not create, and unfamiliar app permissions on the account. Active monitoring of Microsoft 365 sign-in and audit logs is how these get caught.
Is a $320-a-month phishing kit really a threat to a small business? Yes, and the price is the reason. A cheap subscription means a wide pool of low-skill attackers can now run campaigns that used to require real expertise. Small and mid-sized businesses are frequently the target precisely because they are assumed to have fewer defenses after the login step.
What is the single most effective thing to do first? Move your highest-risk accounts, administrators and anyone who touches money, to phishing-resistant MFA and enforce conditional access that checks the device and location. Those two changes close most of the gap this kit exploits.
Since 2002, centrexIT has been the IT and cybersecurity partner for businesses across the western U.S. If your Microsoft 365 defenses stop at the login screen, it is worth finding out where the gaps really are. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/cyber-security-readiness-assessment/
Sources
- NovaCookies is an AitM phishing kit that proxies Microsoft 365 sign-ins and captures authenticated sessions, sold as a subscription at roughly $320 per month: The Hacker News, “NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions” (2026)
- Adversary-in-the-middle phishing relays credentials and MFA in real time to steal session cookies, enabling account takeover and business email compromise: Microsoft Security Blog, “From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud” (2022)
- CISA states that FIDO and WebAuthn is the only widely available phishing-resistant authentication, and that the FIDO protocol will block the attempt when a user is tricked into logging into a fake website: CISA, “More than a Password” (2026)
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team