Somewhere out there, a phishing operator is running a $320-a-month subscription business, complete with a dashboard, uptime, and presumably a Stripe invoice. That’s NovaCookies, the adversary-in-the-middle kit that’s been quietly harvesting Microsoft 365 sessions by riding on genuine Docusign notification emails. It’s a good week to think about cybersecurity the way an attacker does: not as a wall to breach, but as a subscription service to rent. And it’s an even better week to ask a question almost nobody in your org can answer off the top of their head: who actually has admin rights in your directory right now?

Illustration representing session cookie theft in phishing attacks
Session cookies, not passwords, are the real prize in modern phishing kits.

MFA Isn’t the Finish Line Anymore

Here’s the part that should bother you more than the price tag. NovaCookies doesn’t need your password, and it doesn’t care that you’ve got MFA turned on. It sits in the middle of a real login flow, proxies the whole thing including a legitimate-looking Docusign trigger, and walks away with the authenticated session cookie once the user clears the multi-factor prompt themselves. At that point the attacker isn’t guessing credentials in a brute-force loop against your login page. They’re holding a fully authenticated session, which is a very different problem than the one most security awareness training still teaches people to spot.

This is the quiet failure mode of a lot of threat-protection programs: they were built to stop credential theft, and credential theft increasingly isn’t the goal. The goal is the token. Once an attacker has it, your firewall never sees anything unusual, because from the network’s perspective, it’s just you, logging in from wherever you always log in from, except it isn’t.

Quick, Who Has Admin in Your Tenant?

This is where the SANS Internet Storm Center piece on Entra ID admin rights lands at exactly the right moment. The point isn’t exotic. It’s the same question sysadmins have been asking about local admin groups since Windows NT: who can change things, who can delete things, and does that list actually match the list of people who should be able to?

The uncomfortable answer at most organizations is no. People get Global Administrator during a migration project and keep it for three years. Contractors get elevated for a weekend and never get demoted. Someone moves from IT into a different department and nobody remembers to strip their roles. None of that shows up on a dashboard unless someone goes looking, and most teams don’t go looking until something’s already on fire.

The Cybersecurity Blind Spot Nobody Budgets For

Put those two stories next to each other and the shape of the actual risk becomes obvious. Cybersecurity teams spend real money on threat detection tooling, phishing simulations, and endpoint agents, and that’s not wasted effort. But none of it changes the blast radius of a single stolen session if that session belongs to an account sitting on unnecessary admin rights. A commodity phishing kit renting for less than most people’s cable bill, pointed at the right inbox, inherits whatever privilege that inbox’s owner happens to be carrying. If that’s a help desk account with no elevated roles, you have an incident. If it’s an unaudited Global Admin from a project that wrapped up eighteen months ago, you have a tenant-wide compromise.

This is defense in depth in its most literal, least glamorous sense. It’s not one clever control. It’s the boring stack of them working together: identity hardening, session monitoring, and privilege minimization, so that any single failure, including a well-crafted AitM phish that gets past a distracted employee, doesn’t cascade into total loss.

Screenshot representing a fake Docusign notification used in phishing campaigns
Genuine-looking Docusign notifications are the lure NovaCookies rides in on.

What To Actually Do About It

None of this requires exotic tooling. It requires someone to actually own the process, on a recurring calendar invite, not a one-time cleanup that happens after an audit finding.

  • Pull a full export of privileged role assignments in your identity provider today, not next quarter, and confirm every name on it still needs to be there.
  • Move standing admin access to just-in-time elevation wherever your platform supports it, so privilege exists for minutes, not years.
  • Turn on sign-in risk and token protection policies that flag sessions used from an unexpected device or location, since AitM kits can steal the cookie but usually can’t perfectly replicate the device fingerprint.
  • Shorten session and refresh token lifetimes for privileged accounts specifically, even if you leave standard users on longer windows.
  • Build session revocation into your incident response playbook as a first move, not an afterthought, since a stolen cookie is useless the moment the session behind it is killed.
  • Re-run the admin rights audit quarterly and log who approved each grant and why, so the list doesn’t quietly drift back to where it started.

Security hardening isn’t a project with an end date. It’s closer to yard work. Skip it for a season and it doesn’t stay the way you left it.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.