Return to Global Matrix
CLASSIFIED: EYES ONLY

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

TELEMETRY SUMMARY DECRYPTION

SITREP: SECTOR | PRIMARY TARGET | COORDINATES | ALERT LEVEL ------------|----------------------|-------------|------------ Cybersecurity | Microsoft 365 Users | 0.0 | High Cybersecurity researchers have identified a new phishing toolkit named NovaCookies, which operates as an adversary-in-the-middle to capture Microsoft 365 session credentials. This toolkit is marketed as a subscription service, priced at $320 per month, indicating a professional level of cybercriminal activity. TACTICAL ASSESSMENT: The emergence of the NovaCookies toolkit highlights a significant escalation in phishing tactics targeting enterprise-level services like Microsoft 365. This could lead to increased vulnerabilities for organizations relying on these platforms, necessitating enhanced security measures. PROJECTED VECTORS: It is likely that we will see a rise in similar phishing campaigns as cybercriminals adopt and adapt this toolkit for broader exploitation.

OSINT Verification & Telemetry SOPStandard cryptographic auditing active for active node aggregation.

All incoming broadcasts compiled within the Global Matrix intelligence database undergo immediate validation under military-grade Open Source Intelligence (OSINT) standard operating procedures. The Command Center continuously monitors public government RSS channels, cybersecurity alert logs (such as CISA registers), global diplomatic feeds, and authenticated defense bulletins to cross-reference unfolding geopolitical situations.

Signals are ingested autonomously by our secure serverless pipelines, cryptographically verified to establish lineage, and summarized using curated, context-aware artificial intelligence. This workflow preserves the semantic integrity of the primary publisher while extracting key tactical vectors to deliver immediate global telemetry directly to tracking arrays.

Operational Directives:
  • Permanent logging active. Secure external uplink buttons are mapped dynamically to direct source nodes.
SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-08-31

Event Telemetry

STATUS IDENTIFIERNORMAL TRAFFIC
ORIGIN DESKCYBER
ACQUISITION TIME08/2614:54 ZULU
AUTHORSYSTEM.AUTO[992]

Tactical share & deploy