ZeroHour

Search: “microsoft 365”

457 stories

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies AitM phishing kit, a Sneaky 2FA variant, uses genuine Docusign lures to steal Microsoft 365 sessions at hundreds of organizations.

Island disclosed NovaCookies, a $320/month adversary-in-the-middle phishing-as-a-service platform that relays Microsoft 365 sign-ins through attacker infrastructure to capture credentials, MFA codes, and authenticated sessions. Campaigns abuse genuine Docusign envelopes and Microsoft/Google redirect hops so each step looks legitimate, with lure domains on .vu and alternating-case labels such as PwPt-sHaRe. Proofpoint assesses NovaCookies as a Sneaky 2FA variant with added flows for Okta and Entra domains federated to GoDaddy, and a fully managed PhaaS model. It has targeted hundreds of organizations in the U.S., U.K., Canada, Germany, Israel, and the U.A.E., and is advertised via Telegram with anti-analysis checks like a Cloudflare gate.

The Hacker News · 15d agoPhishing & fraud

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

The BigBear 2.0 phishing-as-a-service framework bypassed MFA to steal 5,000+ Microsoft 365 credentials across 258 organizations, CloudSEK researchers found.

CloudSEK researchers gained administrator access to the BigBear 2.0 control panel, finding the phishing-as-a-service operation ran 42 VPS nodes all configured to target Microsoft 365. The framework has been used to bypass multi-factor authentication at 258 organizations and harvest more than 5,000 credentials, indicating an active credential-theft campaign against enterprise tenants.

DataBreaches.net · 8d agoPhishing & fraud in the wild

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

New NovaCookies adversary-in-the-middle phishing kit lets low-skill actors steal Microsoft 365 session cookies for $320 per month.

Dark Reading reports on NovaCookies, an adversary-in-the-middle (AitM) phishing service sold for roughly $320 per month. The kit lowers the barrier to entry for attackers to run credential-harvesting attacks against Microsoft 365. It goes beyond credentials by stealing active session cookies, enabling account takeover without triggering MFA.

Dark Reading · 21d agoPhishing & fraud