'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
NovaCookies offers adversary-in-the-middle M365 session theft at just $320/month, commoditising attacks that bypass conventional MFA — enterprises still relying on push-based authentication face escalating exposure.
Summary written by editorial AI · Source link below
The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.
Editorial Analysis
Commoditised AitM phishing kits make session hijacking accessible to low-skill attackers, rendering push-based MFA insufficient for enterprise Microsoft 365 protection.
Accelerate migration to phishing-resistant authentication (FIDO2/passkeys) and implement token-binding or continuous-access evaluation in Entra ID.
Session-stealing phishing kits are now sold as cheap subscriptions — traditional MFA no longer stops them; phishing-resistant alternatives are essential.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d