Basiran is a reporter for Tech Ledgers covering Cybersecurity & Privacy. She/He is based in Indonesia.
26 August 2026 • 8 min read
The cybercrime ecosystem has undergone a profound industrialization over the past several years, shifting away from bespoke, artisan attacks toward highly scalable, subscription-based business models. At the forefront of this evolution is Phishing-as-a-Service (PhaaS), a commercialized model that lowers the technical barrier to entry, empowering low-skill threat actors to execute sophisticated campaigns targeting enterprise environments.
Executive Overview
Recent intelligence disclosures from cybersecurity researchers at Island, Proofpoint, and Sublime Security have exposed a new generation of these attack platforms. Chief among them is NovaCookies, a $320-per-month adversary-in-the-middle (AitM) phishing toolkit capable of bypassing standard multi-factor authentication (MFA) protocols in real time. Alongside NovaCookies, researchers have flagged emerging variants like EvilTokens and sophisticated campaigns run by threat actors such as DOUBLOON DREDGER, which abuse trusted SaaS platforms like Notion and authentic document workflows like Docusign to evade detection.
This report provides an in-depth, authoritative analysis of the NovaCookies platform, its architectural connection to legacy kits like Sneaky 2FA, the multi-layered evasion tactics utilized in current campaigns, and the broader macro-trends reshaping the global threat landscape.
Detailed Chronology and Attack Architecture
The Mechanics of NovaCookies
NovaCookies represents an evolution in proxy-based credential harvesting. Unlike older phishing paradigms that simply logged static username and password pairs—often rendered ineffective by modern MFA implementations—AitM kits function as live intermediaries between the victim and the target identity provider (IdP).
When a target interacts with a NovaCookies campaign, the attack sequence unfolds through several carefully orchestrated stages:
The Trusted Delivery Vector: Campaigns utilizing NovaCookies frequently originate via legitimate channels. Attackers have been observed leveraging genuine Docusign notification envelopes to distribute counterfeit document-share requests. Because the emails originate from authentic Docusign infrastructure, they sail past traditional sender-authentication checks, SPF, DKIM, and DMARC verifications.
Obfuscated Payloads and Redirect Hops: Embedded within the Docusign notifications are links pointing to malicious PDFs or document-sharing portals. Clicking these links routes victims through legitimate Microsoft or Google sign-in endpoints as intermediate redirect hops. This clever maneuver manipulates reputation filters and security scanners, making the initial path appear entirely benign up until the browser reaches the attacker-controlled proxy infrastructure.
Multi-Identity Provider (IdP) Targeting: While earlier iterations of this codebase (such as the Sneaky 2FA kit documented by Proofpoint) focused heavily on standard Microsoft consumer and enterprise accounts, NovaCookies has expanded its footprint. It includes dedicated authentication flows for alternative identity providers, notably Okta and Microsoft Entra domains federated to GoDaddy.
Real-Time Proxying and Session Hijacking: Once the victim lands on the spoofed login page—which mimics Microsoft 365, Okta, or other enterprise login portals with uncanny fidelity—they are prompted for their credentials and MFA codes. The NovaCookies infrastructure acts as a transparent proxy, passing these inputs to the legitimate IdP in real time. Upon successful validation, the genuine IdP issues session tokens, which are instantly captured by the NovaCookies proxy. Armed with these session cookies, the attacker bypasses MFA entirely and gains unauthorized access to the victim’s account.
Infrastructure and Centralized PhaaS Delivery
A critical differentiator between NovaCookies and older, decentralized phishing kits is its operational model. Historically, affiliates running phishing campaigns were responsible for hosting, maintaining, and securing their own backend infrastructure.
NovaCookies, however, operates on a fully managed PhaaS model. Affiliates pay a monthly subscription fee of approximately $320 to access the platform. Crucially, the underlying infrastructure is hosted centrally by the PhaaS operator rather than the individual affiliate.
The platform’s administration, customer profile management, redirect configuration, and support channels are heavily integrated into encrypted messaging applications, primarily Telegram. This centralized approach allows the operators to quickly patch burned domains, optimize anti-analysis mechanisms, and update credential-harvesting modules without requiring action from individual threat actors utilizing the service.
Supporting Context, Indicators, and Metrics
Geographic and Sector Impact
Telemetry data shared by Island indicates that NovaCookies campaigns have targeted hundreds of organizations across multiple critical sectors. The geographic spread is broad, impacting entities in:
The United States
The United Kingdom
Canada
Germany
Israel
The United Arab Emirates
Because NovaCookies targets core administrative and cloud-identity platforms, the sectors compromised span finance, healthcare, legal services, and technology.
Evasion Techniques: From TLDs to Anti-Analysis Gates
To ensure longevity and evade automated security analysis, NovaCookies campaigns incorporate several layers of defense-evasion engineering:
Top-Level Domain (TLD) Abuse: A significant portion of NovaCookies lure domains have been hosted on the .vu (Vanuatu) country-code TLD (e.g., patterns resembling fordmotbvmorcompany[.]vu).
Alternating-Case URL Labeling: To trick casual human inspection and bypass naive keyword blacklists, phishing URLs frequently employ alternating-case labels, such as PwPt-sHaRe, Ms36-AcCeSs, and ClOd-ViEw.
Anti-Analysis Gates: Before serving the malicious login page, the platform subjects incoming traffic to rigorous screening. This includes Cloudflare-managed gates and detection mechanisms designed to identify execution environments, automated sandboxes, and debugging tools typically utilized by security researchers and automated crawlers.
The DOUBLOON DREDGER Campaign and Notion Abuse
Parallel to the rise of NovaCookies, threat tracking groups have identified other threat actors leveraging legitimate SaaS platforms to distribute credential-harvesting kits. Notably, a financially motivated actor tracked as DOUBLOON DREDGER has been observed abusing Notion accounts to host malicious content.
According to Sublime Security, DOUBLOON DREDGER uses Notion to acquire a reputable sender identity and robust hosting infrastructure. Targets are invited to view a document hosted on Notion containing a PDF.
The PDF is generated using specialized builders designed to include two to three overlapping, invisible links. This redundant linking structure increases the shelf-life of the malicious PDF by confounding defensive parsers. When clicked, the victim is directed to a landing page featuring advanced JavaScript obfuscation and encryption techniques closely tied to Tycoon 2FA and EvilTokens device code harvesting campaigns.
Official Statements and Industry Insights
The proliferation of these automated platforms has alarmed cybersecurity analysts worldwide. Security researchers emphasize that the threat no longer lies solely in the novelty of the phishing lure, but in the seamless integration of enterprise-grade tooling into underground criminal ecosystems.
"While the original Sneaky2FA appeared to focus mainly on Microsoft accounts, the NovaCookies variant includes dedicated flows for other identity providers, including Okta, and Entra domains federated to GoDaddy," noted Proofpoint threat analysts in an advisory statement.
Island highlighted the psychological and perceptual challenge these multi-hop attacks pose to end-users:
"NovaCookies is built so each hop can look legitimate on its own: a trusted delivery service, an identity-provider redirect, then a familiar sign-in page. Those pieces often land in different tools. The browser is where they become a single event."
Furthermore, the emergence of platforms like EvilTokens points to an alarming shift in the PhaaS capability curve. Flare security researcher Assaf Morag observed:
"EvilTokens represents a structural shift in the PhaaS market. Previous platforms commoditized the front end of the attack: the lure, the landing page, the credential capture. EvilTokens commoditizes what comes after."
"By automating inbox analysis, stakeholder mapping, and AI-generated fraud messages, it removes the skill barrier that once separated a captured token from a successful financial compromise. An affiliate no longer needs to understand business email compromise tradecraft, as the platform provides it as a feature."
Future Outlook and Defensive Recommendations
As PhaaS kits like NovaCookies, EvilTokens, and Tycoon 2FA continue to lower the entry barrier for cybercriminals, organizations must fundamentally rethink their perimeter defense and identity verification strategies. Traditional security awareness training that relies solely on spotting misspelled domains or suspicious email headers is increasingly ineffective when attackers utilize legitimate infrastructure—such as Docusign and Notion—to deliver payloads.
To mitigate the risks posed by modern Adversary-in-the-Middle and session-hijacking frameworks, enterprise security leaders should consider the following strategic measures:
Deploy Phishing-Resistant MFA: Move away from SMS-based codes, push notifications vulnerable to number-fatigue, and standard software OTPs. Implement hardware-bound credentials compliant with FIDO2 / WebAuthn standards (such as security keys or platform authenticators like Windows Hello and Apple TouchID/FaceID). Because FIDO2 keys cryptographically bind the authentication session to the origin URL, AitM proxies cannot relay these credentials to a third-party site.
Implement Continuous Session Monitoring: Because AitM toolkits harvest active session cookies rather than static passwords, standard sign-in logs may not trigger traditional alerts. Organizations should deploy User and Entity Behavior Analytics (UEBA) to detect anomalous session behavior, such as impossible travel, sudden changes in user-agent strings, or unexpected administrative actions executed immediately following a login.
Strengthen Email Security and URL Rewriting: Security tools must look beyond basic reputation scoring of sender domains. Email security gateways should perform deep document inspection—parsing PDF contents and embedded hyperlink structures rather than trusting the top-level container or delivery service blindly.
Enforce Conditional Access Policies: Restrict cloud resource access based on device compliance and managed endpoint status. Utilizing secure enterprise browsers or isolated workspace environments can prevent session tokens from being exported or exfiltrated by rogue browser extensions or proxy-intercept mechanisms.
The commercialization of advanced cybercrime infrastructure guarantees that kits like NovaCookies will remain a persistent threat. Only through a defense-in-depth architecture that assumes perimeter compromise and enforces strict, phishing-resistant identity controls can modern enterprises hope to neutralize real-time session theft.