The Rise of "NovaCookies": Inside the $320-a-Month Phishing-as-a-Service Industry

The cybersecurity landscape is undergoing a profound transformation, characterized by the professionalization of cybercrime. A new report from Island, an enterprise browser provider, has shed light on "NovaCookies," a sophisticated phishing-as-a-service (PaaS) operation that is effectively commoditizing the theft of Microsoft 365 sessions. For a subscription fee of roughly $320 per month, cybercriminals are gaining access to high-fidelity tools capable of bypassing multi-factor authentication (MFA) at scale, putting hundreds of organizations across the globe in the crosshairs.

The Mechanics of NovaCookies: Commoditized Identity Theft

At its core, NovaCookies is not merely a phishing kit; it is a turnkey infrastructure designed to circumvent the modern security stack. The service allows threat actors to execute real-time session hijacking—a technique that moves beyond simple credential harvesting to intercepting the actual session tokens issued by Microsoft 365. By stealing these tokens, attackers can bypass MFA entirely, gaining persistent, authenticated access to corporate environments as if they were the legitimate user.

The brilliance of the NovaCookies model lies in its "ease of use" for the attacker. By lowering the barrier to entry for complex, session-based attacks, the service has enabled a broader range of malicious actors to conduct high-impact breaches that were previously reserved for well-funded, advanced persistent threat (APT) groups.

Chronology of a Campaign: From Lure to Hijack

The lifecycle of a NovaCookies-backed attack is a study in precision social engineering. Researchers at Island tracked the campaign’s evolution, identifying a systematic approach to compromise.

Phase 1: The Trust-Based Lure

The campaign typically begins with the delivery of a fraudulent document-share link. To increase the likelihood of success, attackers are increasingly leveraging legitimate platforms such as DocuSign. By sending emails through these trusted services, the attackers bypass traditional email filtering systems that look for suspicious domains or malicious attachments. The recipient, familiar with the DocuSign interface, is far more likely to engage with the link.

Phase 2: The Redirect Cascade

Once the user clicks the link, they are not immediately funneled to an attacker-controlled site. Instead, the traffic is routed through legitimate sign-in endpoints belonging to Microsoft or Google. This creates a "trust veneer"; when the user looks at the URL in their browser address bar, it often appears as a legitimate authentication portal. This step is critical in desensitizing the target and ensuring the link passes the scrutiny of security awareness training.

Phase 3: The Authentication Relay

After navigating the initial redirects, the user is eventually funneled into the NovaCookies infrastructure. Here, the phishing kit acts as an "adversary-in-the-middle" (AITM). The user is prompted to enter their credentials and complete their MFA challenge. As the user performs these actions, the NovaCookies kit relays them to the legitimate Microsoft service in real-time. Once the authentication is successful, the service captures the resulting session cookie.

Phase 4: Session Persistence

The attacker, now in possession of the session cookie, imports it into their own browser. Because the session is already authenticated, the attacker is granted full access to the victim’s account—bypassing the need for passwords or further MFA prompts. The attacker can then maintain this access until the session expires or the user logs out, providing ample time to exfiltrate sensitive data, initiate business email compromise (BEC), or move laterally through the corporate network.

Supporting Data: The Scope of the Threat

The research provided by Island offers a chilling look at the reach of NovaCookies. By analyzing artifacts associated with the campaign, investigators discovered that the infrastructure has been used to target hundreds of diverse organizations.

Geographic Distribution

The United States remains the primary target, accounting for 49.2% of the observed phishing activity. This is consistent with the broader trend of cybercriminals focusing on organizations with the highest potential for financial gain or valuable intellectual property.

Domain Infrastructure

A significant portion of the campaign—nearly 90%—utilized lures hosted on .vu (Vanuatu) domains. The reliance on this specific top-level domain suggests that the operators of NovaCookies have established a preferred, low-cost registration pipeline to facilitate their operations.

Defensive Countermeasures

The NovaCookies kit is specifically engineered to defeat automated security scanners. It employs:

  • Short-lived context binding: Ensuring that the phishing page is only valid for a specific target or timeframe, making it difficult for automated crawlers to capture the full attack chain.
  • Proof-of-Work (PoW) challenges: Forcing the visiting client (or scanner) to perform computationally expensive tasks before the page loads, which effectively filters out many automated security bots.
  • Browser-based checks: Assessing the environment of the visitor to ensure they are using a legitimate browser session before serving the phishing content.

Implications for Modern Enterprise Security

The emergence of NovaCookies signifies a paradigm shift in how we must view identity and access management. Traditional MFA, once considered the "gold standard" for security, is no longer the panacea it once was.

The Death of Traditional MFA

As session hijacking becomes more prevalent and easier to execute via services like NovaCookies, organizations must transition to more resilient authentication methods. FIDO2-compliant security keys, which are resistant to AITM attacks, represent the next frontier in defense. Because these keys rely on hardware-bound cryptographic challenges, they cannot be "relayed" by a phishing kit, effectively neutralizing the NovaCookies threat model.

The Role of the Managed Browser

The report from Island emphasizes the need for an enterprise-grade browser environment. By controlling the browser, organizations can enforce security policies that extend beyond the network perimeter. If an enterprise browser is used, the organization can detect the anomalous behavior of session-stealing kits or restrict the ability of sessions to be exported or utilized outside of a managed environment.

The Human Element

Despite the technological sophistication of NovaCookies, the attack still relies on the human clicking the link. While the lures are increasingly deceptive, security awareness training remains a fundamental pillar. Organizations should specifically educate employees on the dangers of "trusted" document-sharing platforms being used for malicious purposes and reinforce the importance of inspecting URLs, even when they appear to originate from familiar services.

Conclusion: A Persistent Threat

The NovaCookies service is a stark reminder that the barrier to conducting advanced cyberattacks is falling. When $320 is all it takes to acquire the tools to bypass MFA and hijack corporate sessions, the threat landscape shifts from a few elite hacking groups to a massive, decentralized network of opportunistic criminals.

As organizations move forward, the focus must shift from simple perimeter defense to a philosophy of "assumed breach." Protecting identity must become the primary concern, requiring the adoption of phishing-resistant MFA, continuous session monitoring, and the implementation of enterprise-grade browser security. NovaCookies may be the latest threat to emerge, but the underlying vulnerability—the trust we place in a simple session token—is a systemic issue that requires a robust and immediate industry-wide response.

The battle against session hijacking is far from over; it is only just beginning. As cybercriminals continue to refine their kits to evade detection, the resilience of our digital infrastructure will be tested in ways we are only just beginning to quantify. Organizations that fail to adapt their security posture to account for these new, commoditized attack vectors will find themselves increasingly vulnerable in an era where trust is the most exploited commodity of all.