All Articles

NovaCookies and the New AitM Playbook: 2026 Phishing Red Flags

August 27, 2026 5 min read By The Vici Tech Solutions Team
PhishingSocial EngineeringThreat IntelligenceCyber Security

The $320 Phishing Kit That Bypasses MFA

Phishing has evolved far beyond misspelled emails and suspicious attachments. This week, researchers disclosed NovaCookies, a new adversary-in-the-middle (AitM) phishing toolkit that sells for just $320 per month and enables attackers to steal active Microsoft 365 sessions—even when multi-factor authentication is enabled.

Unlike traditional phishing that simply harvests credentials, AitM attacks intercept the entire authentication process in real-time. When a victim attempts to sign into Microsoft 365, they're actually communicating through an attacker-controlled proxy server that captures not just their username and password, but their session cookies and authentication tokens. The attacker then uses these tokens to impersonate the victim without ever needing to solve the MFA challenge themselves.

What makes NovaCookies particularly concerning is how it abuses legitimate DocuSign notifications to establish trust. Victims receive genuine DocuSign emails directing them to review a document. The attack leverages DocuSign's legitimate infrastructure to bypass email security filters, then redirects users through the malicious proxy during the Microsoft 365 sign-in process.

Why Traditional MFA Isn't Enough

The emergence of affordable AitM toolkits represents a fundamental shift in the phishing landscape. For years, security professionals have recommended MFA as the primary defense against credential theft. While MFA remains essential, session-hijacking attacks demonstrate its limitations.

When an attacker captures your session token, they inherit your authenticated state. From the application's perspective, the attacker is you. They can access your email, download sensitive files, modify permissions, and move laterally through your organization's systems—all without triggering MFA prompts.

This technique isn't entirely new. Microsoft has been warning about AitM phishing since 2022, and toolkits like Evilginx have been available for years. What's changed is the industrialization of these attacks. At $320 per month, NovaCookies brings sophisticated session-hijacking capabilities within reach of low-skill threat actors.

Red Flags for Modern Phishing and Social Engineering

Based on current threat intelligence and the NovaCookies campaign characteristics, here are the concrete warning signs your team should watch for:

Unexpected Authentication Requests

  • Mid-session re-authentication prompts when you haven't logged out or timed out
  • Sign-in requests from legitimate services (DocuSign, Adobe, Dropbox) that you didn't initiate
  • Multiple MFA prompts in rapid succession, especially if you only attempted to sign in once
  • Authentication requests during off-hours when you're not working

URL and Domain Anomalies

  • Slight misspellings in domains that use character substitution (rn instead of m, or unicode lookalikes)
  • Unexpected redirects through unfamiliar domains before reaching the legitimate service
  • Login pages that don't match the SSL certificate or show certificate warnings
  • URLs with excessive subdomains or unusual top-level domains (.tk, .ml, .ga)

Behavioral Inconsistencies

  • Urgent requests from executives or vendors asking you to review documents or approve transactions, especially via unexpected channels
  • Requests that bypass normal approval workflows or ask you to use personal devices
  • Pressure to act immediately with threats of missed deadlines or security consequences
  • Communications that reference recent news events or ongoing projects to establish false legitimacy

Technical Indicators

  • Login pages that load slowly or show unusual formatting (often a sign of proxy latency)
  • Requests to install browser extensions or certificates as part of the authentication process
  • Popups or overlays during the sign-in process that don't match the service's standard authentication flow

Defense Strategies That Actually Work

Protecting against AitM phishing requires a layered approach that goes beyond basic MFA:

Implement Phishing-Resistant Authentication

  • Deploy FIDO2 security keys or Windows Hello for Business for privileged accounts
  • Use certificate-based authentication where hardware tokens verify both the user and the authentication server
  • Enable conditional access policies that restrict sign-ins based on device compliance, location, and risk signals

Strengthen Session Management

  • Reduce session token lifetime to limit the window of opportunity for stolen tokens
  • Implement continuous authentication that re-evaluates trust throughout the session
  • Monitor for impossible travel scenarios where a user's session appears in geographically distant locations within a short timeframe
  • Require re-authentication for sensitive actions like permission changes or data exports

Enhance Email and Link Security

  • Deploy URL rewriting and sandboxing that inspects links before users click them
  • Use DMARC, DKIM, and SPF to prevent domain spoofing
  • Implement Safe Links protection that checks URLs at click-time, not just delivery
  • Establish out-of-band verification procedures for sensitive requests received via email

User Awareness and Reporting

  • Train staff to verify unexpected authentication requests by navigating directly to the service rather than clicking links
  • Create a culture where reporting suspicious emails is encouraged without fear of judgment
  • Conduct realistic phishing simulations that include AitM techniques, not just traditional credential harvesting
  • Establish clear escalation procedures for security incidents

The Broader Context: Active Exploitation and Critical Patches

While phishing remains the primary initial access vector, this week's threat landscape includes multiple actively exploited vulnerabilities. CISA added six new flaws to its Known Exploited Vulnerabilities catalog, including a critical Citrix NetScaler ADC remote code execution vulnerability (CVE-2026-8452) that federal agencies must patch by Saturday.

The combination of sophisticated phishing techniques and unpatched vulnerabilities creates a perfect storm for breaches. As we saw in CISA's red team assessment report, one of two critical infrastructure organizations detected nothing during a simulated compromise. The attackers gained initial access through phishing, then exploited unpatched systems to establish persistence.

Action Items for IT Managers

If you manage authentication and access for your organization, prioritize these steps this week:

  1. Audit your current MFA implementation and identify privileged accounts that should use phishing-resistant authentication
  2. Review session timeout policies and reduce token lifetime for sensitive applications
  3. Enable conditional access policies that flag unusual sign-in patterns
  4. Patch Citrix NetScaler systems immediately if you use them (CVE-2026-8452)
  5. Test your incident response procedures for compromised credentials and stolen sessions
  6. Schedule tabletop exercises that include AitM phishing scenarios

The threat landscape continues to evolve, but the fundamentals remain constant: defense in depth, continuous monitoring, and rapid response. AitM phishing toolkits like NovaCookies demonstrate why single-layer defenses fail and why security must be an ongoing process, not a checklist.

If you need help assessing your organization's resilience against modern phishing attacks or want to conduct realistic security testing, Vici Tech Solutions offers penetration testing and security assessments tailored to the current threat landscape.

Worried about the threats you just read about?

Vici Tech Solutions helps businesses across the US find and fix vulnerabilities before attackers do. Explore our penetration testing services or talk to us about your security posture.

Get a Security Assessment