← Back
PhishingDark Reading·4 hours ago

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

A new phishing-as-a-service offering called NovaCookies enables attackers to conduct adversary-in-the-middle attacks against Microsoft 365 users, available for $320 monthly. Rather than simply capturing credentials, the kit specifically targets and exfiltrates active session cookies, giving threat actors direct account access without needing passwords. This lowered barrier to entry could expand the pool of actors capable of launching sophisticated session-hijacking campaigns against enterprise targets.

Read full article at Dark Reading

Related Articles

PhishingThe Hacker News·2 hours ago

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

A new adversary-in-the-middle phishing toolkit called NovaCookies leverages legitimate DocuSign notifications to trick users into authenticating through malicious proxies that capture their Microsoft 365 sessions. The subscription-based service, priced at $320 per month, intercepts and redirects sign-in attempts while harvesting authenticated session credentials from victims.

PhishingHelp Net Security·3 hours ago

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

AnonyMousKIT, a phishing-as-a-service platform discovered by SOCRadar, uses AI-generated voice calls impersonating Apple Support to trick users into revealing iPhone passcodes and Apple ID credentials needed to bypass Activation Lock on stolen devices. The operation has maintained a network of 506 domains and 168 storefronts since early 2024, though researchers exposed the infrastructure through basic coding errors that left production logs and operator information accessible. Despite its sophisticated AI voice technology, the platform's reliance on bare relative paths and poor security practices made it vulnerable to investigation and takedown efforts.

PhishingHelp Net Security·6 hours ago

Bogus recruiters go after high-value corporate credentials on mobile

Threat actors impersonating HR recruiters are targeting corporate credentials through fake interview scheduling flows on mobile devices, leveraging scraped public profile data to increase credibility. The attackers employ browser-in-the-browser (BitB) techniques to create convincing phishing pages that bypass user skepticism and extract corporate passwords from high-value targets.

PhishingThe Hacker News·10 hours ago

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Researchers have uncovered a phishing-as-a-service platform called AnonyMousKIT that uses AI voice agents to impersonate Apple Support and target owners of stolen devices, attempting to extract passcodes and two-factor authentication codes to bypass Activation Lock. The credit-metered service automates social engineering attacks by calling victims and deceiving them into revealing sensitive authentication credentials. This approach represents an evolution in device theft operations, combining AI-driven voice phishing with stolen device monetization tactics.