You Can’t Dunk NovaCookies in Milk

31266419499?profile=RESIZE_180x180Security researchers have uncovered NovaCookies, a phishing-as-a-service platform that helps criminals steal Microsoft 365 authentication sessions in real time.  The platform gives attackers infrastructure that relays a genuine Microsoft sign-in page through attacker-controlled systems.  Victims are directed to what appears to be a legitimate login process, allowing the service to collect credentials and intercept the authenticated session after the user enters a password and completes multi-factor authentication (MFA).[1]

Island, the security company behind the research, said the discovery demonstrates how phishing operations are becoming easier to launch and maintain. Rather than developing a new software vulnerability, operators can subscribe to an established service and use its infrastructure against multiple organizations.

Shachar Gritzman, Senior Security Researcher at Island, said NovaCookies was notable because it made real-time session theft commercially accessible. “What makes NovaCookies notable is not a new exploit,” Gritzman said. “It packages real-time Microsoft 365 session theft as a subscription service advertised at $320 a month.”

The service reportedly relays a genuine Microsoft sign-in through attacker-controlled infrastructure. This lets attackers capture an active session after both the password and MFA steps are complete.  That distinction matters because conventional MFA can be defeated when criminals intercept an authenticated session rather than trying to guess or steal a password.  Once obtained, a session may allow an attacker to access corporate email, cloud files and other Microsoft 365 resources without immediately triggering another authentication request.

Island’s review found that hundreds of organizations appeared among the targets linked to the activity. Nearly 90% of organizations in the reviewed dataset were associated with phishing lures hosted on .vu domains, the country-code domain assigned to Vanuatu.  The finding does not mean every .vu website is malicious. However, the concentration of observed lures on that domain suggests that infrastructure choices may help investigators identify related campaigns and support defensive monitoring.

Island has released a companion indicator-of-compromise (IOC) set containing 755 domains assessed as dedicated malicious infrastructure associated with the activity. Organizations can use the list to examine network traffic, email records, DNS activity and security alerts for possible connections.

Gritzman cautioned that domain blocking alone would offer only temporary protection. “Phishing-resistant authentication is designed to stop this relay,” he said. “Blocking yesterday’s domain only removes one disposable part of the operation.”

The comment points to a broader challenge for defenders. Criminal services can replace domains, adjust lures and redirect victims through new infrastructure, potentially allowing campaigns to continue after individual indicators have been blocked.

Security teams should therefore combine domain and URL monitoring with phishing-resistant authentication, such as passkeys or hardware-backed security keys. They should also review suspicious sign-ins, revoke potentially compromised sessions, examine mailbox rules and investigate unusual access to cloud files.

The NovaCookies findings highlight the need to treat MFA as one part of a wider identity-security strategy. Staff awareness training, conditional-access policies, device checks and rapid session revocation can reduce the time available to attackers.  The research also reinforces the value of sharing detailed IOCs. While individual domains may be short-lived, a broad set of associated infrastructure can help defenders connect seemingly separate phishing incidents and improve detection across multiple organizations.

For businesses using Microsoft 365, immediate priorities include checking the released domain list, strengthening authentication controls, and preparing procedures for suspected session theft. A successful login should not automatically be treated as proof that an account is safe.

 

This AI created article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

 Weekly Cyber Intelligence Briefings:

 REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://www.cybersecurityintelligence.com/blog/novacookies-phaas-targets-microsoft-365-sessions-9702.html

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!