M365 Session Hijacking and Malware Execution
An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.
Based on research by Cisco Talos 2026-09-28 12 steps · 5 queries T1204.002 T1486 T1539 T1566.002
Brief
Why this hunt
Talos identifies a campaign using the NovaCookies platform to bypass MFA in their article, “Sorry, I can’t help with that”: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/. The adversary uses DocuSign-themed phishing to steal M365 session tokens. This hunt identifies the resulting hijacked sessions and the subsequent malware execution on the endpoint.
How the hunt flows
The hunt starts by listing active Windows workstations. These hosts are the primary targets for the DocuSign phishing lures and the resulting ransomware impact.
Next, the hunt runs two parallel queries. The first query checks DNS activity for resolution of the specific DocuSign phishing and sandbox domains named in the Talos report. The second query looks for successful M365 sign-ins from IP addresses that a user has never used before. This identifies potential session hijacking events.
An automated agent triages these leads. The goal is to find users who resolved a phishing domain and then signed in from an anomalous IP. This correlation identifies compromised identities with high confidence.
The hunt then pivots to endpoint activity for these users. It searches for the execution of specific malware droppers and tools by their SHA256 hashes and filenames. Simultaneously, it monitors file activity for bursts of operations on common document types like Word and PDF files. These spikes in activity often indicate the start of data encryption.
In the final phase, the hunt correlates the identity evidence with the host artifacts. If a host associated with a compromised user shows both malware execution and signs of data encryption, the hunt issues a malicious verdict. The analyst can then isolate the host and revoke the user's M365 sessions.
Blind spots
This hunt cannot see activity on hosts without an endpoint agent. It also relies on detecting the aftermath of session theft rather than the theft itself. If an adversary uses a proxy to match the victim's typical location, the anomalous sign-in query may not trigger. Additionally, the hunt does not examine local browser forensics for direct evidence of cookie extraction.
Steps
-
Scope Windows Workstations
Query · scopingIdentify active Windows hosts that are the primary targets for phishing and subsequent ransomware execution.
reads hb_devicessqlSELECT hostname, os_name, os_version, last_seen FROM hb_devices WHERE platform = 'windows' AND lifecycle_state = 'active' AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. A list of targetable Windows hosts. None means no Windows systems were enrolled or active during the window.
-
DNS Phishing Lures
Query · enrichmentDetect resolution of DocuSign-themed phishing sites or sandbox domains named in the report.
reads hb_dns_activitysqlSELECT device_hostname, query_hostname, COUNT(*) AS total_lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, query_hostnameWhat a hit looks like. Hosts resolving malicious domains; silence means no direct connection to the reported lures occurred.
-
M365 Sign-in Anomalies
Query · baselineFind successful M365 logons from unusual IP addresses per user, suggesting session hijacking.
reads hb_auth_signinsqlSELECT actor_user_name, src_endpoint_ip, COUNT(*) AS logon_count, MIN(time) AS first_logon, MAX(time) AS last_logon FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING logon_count < 5 ORDER BY logon_count ASCWhat a hit looks like. A rare user/IP combination that differs from historical patterns. A single logon from a new IP for a user is a typical hijacking signal.
-
Triage Identity Hijack
Agent triageEvaluate whether the DNS and Auth leads suggest a high-confidence session theft event.
-
Malware Execution
Query · detection candidateDetect the execution of the specific droppers and tools identified by Talos.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_hash_sha256, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{malware_filenames}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)What a hit looks like. Process executions matching the reported malware. Any match is high confidence.
-
Ransomware Impact
Query · triageDetect high-frequency file operations on user document types, characteristic of encryption.
reads hb_file_activitysqlSELECT device_hostname, actor_user_name, COUNT(*) AS op_count, MIN(time) AS first_op, MAX(time) AS last_op FROM hb_file_activity WHERE activity_id IN (1, 4, 5) AND (LOWER(file_path) LIKE '%.docx' OR LOWER(file_path) LIKE '%.xlsx' OR LOWER(file_path) LIKE '%.pdf') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, actor_user_name HAVING op_count > 20What a hit looks like. A burst of file creations, deletions, or renames on document files. Silence means no mass encryption events were detected on the targeted surfaces.
-
Final Correlation Agent
Agent triageSynthesize early identity evidence with endpoint malware and impact findings.
-
Route on Final Verdict
DecisionTrigger containment for confirmed intrusions.
-
Isolate Host
Response actionHalt the ransomware execution and session abuse.
-
Analyst Review
Analyst taskVerify the agent's findings and document the incident lifecycle.
-
Close-out
Analyst taskFinalize documentation and archive the hunt results.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| DocuSign Phishing Lure T1566.002 |
Yes | dns-phishing-lures |
| M365 Session Hijacking T1539 |
Yes | m365-auth-anomaly, agent-identity-triage |
| Malware Dropper Execution T1204.002 |
Yes | malware-execution |
| Data Encryption for Impact T1486 |
Yes | ransomware-impact |
Blind spots
- Needs endpoint agent coverage. A host without an agent could be executing malware undetected even if identity logs show session hijacking. It would answer Are there infected hosts that are not reporting process or file activity?.
- Needs local browser history and cookie artifacts. This hunt relies on identifying the aftermath (anomalous sign-ins) rather than the direct theft, which may allow stealthy proxy usage to go unnoticed. It would answer Can we confirm the browser-level cookie theft event?.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
malware_filenames | list[string] | VID001.exe, client32.exe, WCInstaller_NonAdmin.exe, content.js, SECOH-QAD.exe | Known filenames of malicious droppers observed in recent telemetry. |
malware_hashes | list[hash] | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507, e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47, c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2, 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55, 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f, a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 | SHA256 hashes of malware droppers and tools identified by Talos. |
phishing_domains | list[domain] | 95.sbx.tg, 38d053135d-95.sbx.tg, c4dd71e347-95.sbx.tg, 9f1f11a708-100.sbx.tg | DocuSign phishing and sandbox domains observed in the campaign; docusign.net removed to reduce noise. |
scope_hosts | list[host] | — | Optional list of hostnames to focus the hunt. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Identity / sign-in telemetry | identity | identity |
Source
---
analysis: A single detection rule on malware hashes is easily bypassed by binary rotation.
This hunt correlates cloud identity anomalies with host behavior and file impact,
providing context that a single-surface rule cannot achieve.
blind_spots:
- id: missing-endpoint-visibility
question: Are there infected hosts that are not reporting process or file activity?
requires: endpoint agent coverage
risk: A host without an agent could be executing malware undetected even if identity
logs show session hijacking.
stage: execution-malware-droppers
- id: browser-forensic-gap
question: Can we confirm the browser-level cookie theft event?
requires: local browser history and cookie artifacts
risk: This hunt relies on identifying the aftermath (anomalous sign-ins) rather
than the direct theft, which may allow stealthy proxy usage to go unnoticed.
stage: credential-access-session-theft
coverage:
- stage: initial-access-docusign-phishing
status: covered
steps:
- dns-phishing-lures
- stage: credential-access-session-theft
status: covered
steps:
- m365-auth-anomaly
- agent-identity-triage
- stage: execution-malware-droppers
status: covered
steps:
- malware-execution
- stage: impact-data-encryption
status: covered
steps:
- ransomware-impact
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: M365 session hijacking via phishing platforms like NovaCookies bypasses
traditional MFA. Detecting the subsequent malware execution and ransomware impact
on the same user context provides a high-confidence signal for containing intrusions.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed
phishing, enabling them to execute malicious droppers and deploy ransomware across
the fleet.
labels:
- hunt
- attack.t1566.002
- attack.t1539
- attack.t1204.002
- attack.t1486
name: M365 Session Hijacking and Malware Execution
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
type: number
malware_filenames:
default:
- VID001.exe
- client32.exe
- WCInstaller_NonAdmin.exe
- content.js
- SECOH-QAD.exe
description: Known filenames of malicious droppers observed in recent telemetry.
from:
kind: article
observed: '2026-08-27'
ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
type: list[string]
malware_hashes:
default:
- 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
- e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47
- c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2
- 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55
- 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
- a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91
description: SHA256 hashes of malware droppers and tools identified by Talos.
from:
kind: article
observed: '2026-08-27'
ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
type: list[hash]
phishing_domains:
default:
- 95.sbx.tg
- 38d053135d-95.sbx.tg
- c4dd71e347-95.sbx.tg
- 9f1f11a708-100.sbx.tg
description: DocuSign phishing and sandbox domains observed in the campaign; docusign.net
removed to reduce noise.
from:
kind: article
observed: '2026-08-27'
ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
type: list[domain]
scope_hosts:
default: []
description: Optional list of hostnames to focus the hunt.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Prioritize users with access to sensitive document shares and workstations
in departments commonly receiving DocuSign notifications. Start with a 14-day lookback
to catch the session theft beachhead.
references:
- name: "\u201CSorry, I can\u2019t help with that\u201D: How your guardrails might\
\ become the attacker\u2019s best friend"
url: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
- name: "Talos \u2014 Sorry, I can\u2019t help with that: How your guardrails might\
\ become the attacker\u2019s best friend"
url: https://blog.blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
related:
- hunt: m365-token-theft-browser-forensics
reason: This hunt focuses on network and authentication anomalies; browser-specific
cookie artifacts require a separate forensic hunt.
relation: out-of-scope-alternative
scenario:
stages:
- name: DocuSign Phishing Lure
observables:
- genuine docusign notifications
- docusign.net
- NovaCookies phishing platform
slug: initial-access-docusign-phishing
tactic: initial-access
techniques:
- T1566.002
- name: M365 Session Hijacking
observables:
- M365 session theft
- real-time session hijacking
- $320/month phishing kit
slug: credential-access-session-theft
tactic: credential-access
techniques:
- T1539
- name: Malware Dropper Execution
observables:
- VID001.exe
- client32.exe
- WCInstaller_NonAdmin.exe
- content.js
- SECOH-QAD.exe
- d4aa3e7010220ad1b458fac17039c274_62_Exe.exe
- ToxicPanda banking trojan
slug: execution-malware-droppers
tactic: execution
techniques:
- T1204.002
- name: Data Encryption for Impact
observables:
- ransomware encryption
- file renaming
- inaccessible user files
slug: impact-data-encryption
tactic: impact
techniques:
- T1486
summary: The NovaCookies campaign uses genuine DocuSign notifications to lure users
into Microsoft 365 session theft via a subscription-based phishing kit. Stolen
sessions enable unauthorized access to corporate environments, leading to the
deployment of various banking trojans and droppers like ToxicPanda or VID001.exe,
and eventually culminating in data encryption for impact.
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
identity:
category: identity
name: Identity / sign-in telemetry
telemetry:
- identity
tlp: clear
type: investigation
---
# M365 Session Hijacking and Malware Execution
This hunt follows an attack lifecycle from initial cloud identity theft to endpoint ransomware impact. It begins by identifying suspicious DocuSign-related phishing activity and anomalous M365 sign-ins that suggest session hijacking using the NovaCookies platform. The hunt then pivots to the endpoint to detect the execution of specific malware droppers identified by Talos telemetry and monitors for high-frequency file operations characteristic of data encryption. By correlating cloud authentication anomalies with host-side process and file artifacts, the hunt identifies compromised users and the specific hosts where malicious code established a beachhead.
## scope-windows-workstations
<!-- Scope Windows Workstations -->
Identify active Windows hosts that are the primary targets for phishing and subsequent ransomware execution.
```sqlite target=endpoint role=scoping params=(lookback_days=lookback_days)
~~~yaml
expected: A list of targetable Windows hosts. None means no Windows systems were enrolled
or active during the window.
reads:
- hostname
- os_name
- os_version
- last_seen
- time
silence: not_evidence_of_absence
source: hb_devices
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT hostname, os_name, os_version, last_seen FROM hb_devices WHERE platform = 'windows' AND lifecycle_state = 'active' AND time >= datetime('now', '-{{lookback_days}} days')
```
## early-stage-parallel
<!-- Early Stage Parallel -->
parallel:
- → dns-phishing-lures
- → m365-auth-anomaly
join: → agent-identity-triage
## dns-phishing-lures
<!-- DNS Phishing Lures -->
Detect resolution of DocuSign-themed phishing sites or sandbox domains named in the report.
```sqlite target=endpoint role=enrichment params=(phishing_domains=phishing_domains, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Hosts resolving malicious domains; silence means no direct connection to
the reported lures occurred.
reads:
- device_hostname
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, query_hostname, COUNT(*) AS total_lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, query_hostname
```
## m365-auth-anomaly
<!-- M365 Sign-in Anomalies -->
Find successful M365 logons from unusual IP addresses per user, suggesting session hijacking.
```sqlite target=identity role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A rare user/IP combination that differs from historical patterns. A single
logon from a new IP for a user is a typical hijacking signal.
prevalence:
by: actor_user_name
key:
- src_endpoint_ip
rare_below: 2
reads:
- actor_user_name
- src_endpoint_ip
- provider
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT actor_user_name, src_endpoint_ip, COUNT(*) AS logon_count, MIN(time) AS first_logon, MAX(time) AS last_logon FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING logon_count < 5 ORDER BY logon_count ASC
```
## agent-identity-triage
<!-- Triage Identity Hijack -->
```agent target=hunter
cite: required
context:
- dns-phishing-lures
- m365-auth-anomaly
max_iterations: 4
objective: Identify users who likely fell for a DocuSign phishing lure and subsequently
had their M365 session hijacked. Cite the resolved domain and the anomalous logon
IP.
success_criteria: A list of users with corresponding suspicious IP and DNS evidence.
tools:
- endpoint
- identity
```
## follow-on-parallel
<!-- Endpoint Follow-on Hunt -->
parallel:
- → malware-execution
- → ransomware-impact
join: → follow-on-agent
## malware-execution
<!-- Malware Execution -->
Detect the execution of the specific droppers and tools identified by Talos.
```sqlite target=endpoint role=detection-candidate params=(malware_hashes=malware_hashes, malware_filenames=malware_filenames, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Process executions matching the reported malware. Any match is high confidence.
reads:
- device_hostname
- process_name
- process_hash_sha256
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_hash_sha256, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{malware_filenames}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```
## ransomware-impact
<!-- Ransomware Impact -->
Detect high-frequency file operations on user document types, characteristic of encryption.
```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A burst of file creations, deletions, or renames on document files. Silence
means no mass encryption events were detected on the targeted surfaces.
reads:
- device_hostname
- actor_user_name
- activity_id
- file_path
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, COUNT(*) AS op_count, MIN(time) AS first_op, MAX(time) AS last_op FROM hb_file_activity WHERE activity_id IN (1, 4, 5) AND (LOWER(file_path) LIKE '%.docx' OR LOWER(file_path) LIKE '%.xlsx' OR LOWER(file_path) LIKE '%.pdf') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, actor_user_name HAVING op_count > 20
```
## follow-on-agent
<!-- Final Correlation Agent -->
```agent target=hunter
cite: required
context:
- agent-identity-triage
- malware-execution
- ransomware-impact
max_iterations: 6
objective: Determine if compromised identities from the early stage match users or
hosts where malware and ransomware impact occurred. Issue a malicious verdict if
the killchain is confirmed.
success_criteria: A final verdict per host citing the correlation between identity
theft and malicious endpoint activity.
tools:
- endpoint
- identity
```
## route-decision
<!-- Route on Final Verdict -->
if~: "the follow-on-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-endpoint-visibility)
else: → close-out
## isolate-host
<!-- Isolate Host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the infected host from the network and revoke all M365 session tokens for the affected user account.
```
→ analyst-review
## analyst-review
<!-- Analyst Review -->
```manual target=analyst
Review the correlated evidence: DNS lure resolution, anomalous IP sign-in, and endpoint malware execution. Confirm if the file operations align with a ransomware attack.
```
→ close-out
## close-out
<!-- Close-out -->
```manual target=analyst
Record the hosts and users examined. Note any new phishing domains discovered to update future hunt iterations.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.