Microsoft has a security flaw
A phishing service called NovaCookies lets criminals rent a tool that steals Microsoft 365 logins in real time. It sits between the victim and Microsoft, capturing the password and the multi-factor code, then hijacks the signed-in session.
- Report priority
- Medium
- Targets
- Docusign+2 more
How it works
Attackers send an email that looks like a genuine Docusign document-share notice, with the dangerous link buried inside the shared document rather than in the email itself, and route the click through real Microsoft or Google sign-in pages before it lands on a fake Microsoft 365 login page that relays everything the victim types to the real Microsoft site.
What to do
Be suspicious of any Docusign share notice that leads to a Microsoft sign-in page with an unusual or alternating-case web address such as PwPt-sHaRe or Ms36-AcCeSs.
Verify document-share notices directly in Docusign rather than clicking email links, check the actual address bar before entering a Microsoft password, and if a session may already be stolen, have IT revoke active Microsoft 365 sessions and reset the account's credentials and MFA.
Technical details
Affected software: Docusign, Okta, GoDaddy
NovaCookies is a $320/month adversary-in-the-middle phishing-as-a-service platform, assessed by Proofpoint as a variant of the Sneaky2FA kit but run as centrally hosted infrastructure rather than per-affiliate. It proxies Microsoft 365 (and Okta, GoDaddy-federated Entra) authentication traffic live, capturing credentials and MFA-backed session cookies as victims log in through the fake page. Lures abuse genuine Docusign envelopes and an OAuth error-redirect technique Microsoft documented in March 2026 to route victims through real Microsoft or Google endpoints before reaching attacker infrastructure.vu domains. The kit includes a Cloudflare gate and debugger-detection checks to evade automated analysis, and is sold and supported via Telegram.