A novel phishing service is giving attackers a turnkey solution to steal authenticated Microsoft 365 sessions for only $320 a month, bypassing multifactor authentication (MFA) protections and highlighting the need for more robust security for enterprise email.

Researchers from enterprise browser maker Island discover the adversary-in-the-middle (AitM) phishing service, dubbed “NovaCookies,” which provides lures, domains, hosting, redirects, and support to relay Microsoft 365 logins in real time to steal authenticated sessions, according to a report published today by Shachar Gritzman, a senior security researcher at Island.

NovaCookies — which also includes an option to pay $200 for 14 days — runs like a commercial operation and is targeting hundreds of organizations across multiple regions, with at least 755 domains as part of its dedicated infrastructure. More than half of those organizations are in the US or related to entities in the country, and the infrastructure for the campaign “expanded sharply” from mid-May as it continued to appear through August, Gritzman wrote.

Related:15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Delivery methods varied across campaigns, but included email messages with genuine Docusign envelopes carrying counterfeit document-share lures, with some clicks routed through legitimate Microsoft or Google sign-in endpoints as redirection hops before reaching the kit. “The initial authentication can succeed normally, without malware, an exploit, or a burst of failed logins, so the sign-in event may look ordinary,” Gritzman tells Dark Reading.

The service also includes built-in evasion tactics, including short-lived context binding and runtime inspection, to help make the lures resistant to email scanners, according to Island.

Attackers Pivot to Session Theft

While NovaCookies uses tactics familiar to any AitM phishing attack, several things stand out about the service. One is how it “combines trusted document platforms, legitimate redirects and disposable infrastructure with real-time Microsoft 365 session theft, then sells the complete operation to other attackers,” Gritzman says.

“Building and maintaining an adversary-in-the-middle relay takes specialist work,” he wrote in the report. “Renting one lowers that barrier and gives buyers a maintained sign-in flow, infrastructure rotation, and an operator interface.”

Such platforms “remove the need for extensive technical skills or resources usually required for phishing attacks,” observes Krishna Vishnubhotla, vice president, product strategy at mobile security firm Zimperium.

Related:‘Flying Eagle’ Full-Service Mobile RAT Builder Wings Across China

However, the success of attacks facilitated by NovaCookies ultimately depends on the sophistication of the actor, Gritzman adds. “It lowers the barrier substantially, though it does not make every buyer sophisticated or every campaign successful,” he says.

Another novel aspect of NovaCookies is its pivot to stealing session cookies rather than just passwords, as traditional phishing-as-a-service packages tend to do, Abhishek Agrawal, co-founder and CEO of Material Security, tells Dark Reading.

“This steals the authenticated session itself, which means MFA, the control most organizations still treat as the endgame for phishing, doesn’t factor in at all,” he says. “Once the attacker relays the sign-in and captures the session, they’re inside the account for as long as that session stays valid, and that can be a long time.”

This pivot is likely driven by an industry that’s made credential theft harder through the use of passkeys and WebAuthn, which required attackers to find new ways to acquire credentials, Agrawal says. “Session theft is that pivot, and it’s not surprising to see phishing-as-a-service operators productize it to meet demand,” he says.

Beyond MFA to Secure Authentication

NovaCookies isn’t the only phishing-as-a-service kit to bust MFA, though it does provide a harbinger of things to come and the increasing sophistication of methods of attackers to bypass advanced authentication, experts say. To combat this, then, defenders must reconsider how they protect enterprise application credentials, particularly when it comes to email security.

Related:Agentic Browsers Rewind Web Security by 20 Years

“The uncomfortable implication is that the dominant model of email security, stopping the bad message at the front door, assumes the front door is where the fight happens,” Agrawal says. “If the attacker walks in with a valid session, perimeter detection is irrelevant. The industry has spent a decade talking about zero trust, but that thinking never really reached email and the data behind it.”

He suggests organizations set up defenses “to work at every step of the chain, including after compromise” from the moment an email lure reaches an inbox. “You have to assume some sessions get stolen and build so that a stolen session gets an attacker very little,” he says.

Gritzman’s advice to defenders is different. He believes organizations need to focus securing the browser, “where the fully journey converges,” by putting phishing-resistant authentication and controls inside the live user browsing session.

“Enterprises should assume that a phishing incident may expose an authenticated session, not only a password,” he says. “Prevent the relay with phishing-resistant authentication such as FIDO, starting with privileged and high-impact accounts, and require managed devices where practical. Detect it by correlating the browser journey with device trust, token anomalies and post-authentication activity.”

If a relay still succeeds in getting through, Gritzman suggests that instead of relying on password resets — which is the common practice — organizations also should revoke active sessions and refresh tokens to truly secure a potentially compromised session.





Source link

#

Comments are closed