'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

Refract AI Intelligence Digest

BLUF

Affordable adversary-in-the-middle tooling is enabling widespread Microsoft 365 session hijacking beyond simple credential theft.

NEWS

The NovaCookies kit operates as a subscription service costing $320 per month to facilitate adversary-in-the-middle phishing attacks. It specifically targets Microsoft 365 environments, allowing threat actors to harvest active session tokens rather than relying solely on static credentials.

Why I Care

Organizations face increased risk of account compromise even with strong password policies, as session tokens bypass standard multi-factor authentication. This lowers the barrier for less skilled attackers to execute high-impact breaches affecting any entity using Microsoft 365.

Next Steps

Security teams should immediately enforce Conditional Access policies that block legacy authentication and require device compliance. Implement session protection mechanisms like Continuous Access Evaluation (CAE) to invalidate stolen tokens faster.

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.
Back to Blog Listing

Source: Dark Reading ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.