← All hunts high TLP:CLEAR

M365 Session Hijacking and Malware Execution

An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.

Based on research by Cisco Talos 2026-09-28 12 steps · 5 queries T1204.002 T1486 T1539 T1566.002

Brief

Why this hunt

Talos identifies a campaign using the NovaCookies platform to bypass MFA in their article, “Sorry, I can’t help with that”: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/. The adversary uses DocuSign-themed phishing to steal M365 session tokens. This hunt identifies the resulting hijacked sessions and the subsequent malware execution on the endpoint.

How the hunt flows

The hunt starts by listing active Windows workstations. These hosts are the primary targets for the DocuSign phishing lures and the resulting ransomware impact.

Next, the hunt runs two parallel queries. The first query checks DNS activity for resolution of the specific DocuSign phishing and sandbox domains named in the Talos report. The second query looks for successful M365 sign-ins from IP addresses that a user has never used before. This identifies potential session hijacking events.

An automated agent triages these leads. The goal is to find users who resolved a phishing domain and then signed in from an anomalous IP. This correlation identifies compromised identities with high confidence.

The hunt then pivots to endpoint activity for these users. It searches for the execution of specific malware droppers and tools by their SHA256 hashes and filenames. Simultaneously, it monitors file activity for bursts of operations on common document types like Word and PDF files. These spikes in activity often indicate the start of data encryption.

In the final phase, the hunt correlates the identity evidence with the host artifacts. If a host associated with a compromised user shows both malware execution and signs of data encryption, the hunt issues a malicious verdict. The analyst can then isolate the host and revoke the user's M365 sessions.

Blind spots

This hunt cannot see activity on hosts without an endpoint agent. It also relies on detecting the aftermath of session theft rather than the theft itself. If an adversary uses a proxy to match the victim's typical location, the anomalous sign-in query may not trigger. Additionally, the hunt does not examine local browser forensics for direct evidence of cookie extraction.

Steps

  1. Scope Windows Workstations

    Query · scoping

    Identify active Windows hosts that are the primary targets for phishing and subsequent ransomware execution.

    reads hb_devicessql
    SELECT hostname, os_name, os_version, last_seen FROM hb_devices WHERE platform = 'windows' AND lifecycle_state = 'active' AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A list of targetable Windows hosts. None means no Windows systems were enrolled or active during the window.

  2. DNS Phishing Lures

    Query · enrichment

    Detect resolution of DocuSign-themed phishing sites or sandbox domains named in the report.

    reads hb_dns_activitysql
    SELECT device_hostname, query_hostname, COUNT(*) AS total_lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, query_hostname

    What a hit looks like. Hosts resolving malicious domains; silence means no direct connection to the reported lures occurred.

  3. M365 Sign-in Anomalies

    Query · baseline

    Find successful M365 logons from unusual IP addresses per user, suggesting session hijacking.

    reads hb_auth_signinsql
    SELECT actor_user_name, src_endpoint_ip, COUNT(*) AS logon_count, MIN(time) AS first_logon, MAX(time) AS last_logon FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING logon_count < 5 ORDER BY logon_count ASC

    What a hit looks like. A rare user/IP combination that differs from historical patterns. A single logon from a new IP for a user is a typical hijacking signal.

  4. Triage Identity Hijack

    Agent triage

    Evaluate whether the DNS and Auth leads suggest a high-confidence session theft event.

  5. Malware Execution

    Query · detection candidate

    Detect the execution of the specific droppers and tools identified by Talos.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_hash_sha256, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{malware_filenames}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)

    What a hit looks like. Process executions matching the reported malware. Any match is high confidence.

  6. Ransomware Impact

    Query · triage

    Detect high-frequency file operations on user document types, characteristic of encryption.

    reads hb_file_activitysql
    SELECT device_hostname, actor_user_name, COUNT(*) AS op_count, MIN(time) AS first_op, MAX(time) AS last_op FROM hb_file_activity WHERE activity_id IN (1, 4, 5) AND (LOWER(file_path) LIKE '%.docx' OR LOWER(file_path) LIKE '%.xlsx' OR LOWER(file_path) LIKE '%.pdf') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, actor_user_name HAVING op_count > 20

    What a hit looks like. A burst of file creations, deletions, or renames on document files. Silence means no mass encryption events were detected on the targeted surfaces.

  7. Final Correlation Agent

    Agent triage

    Synthesize early identity evidence with endpoint malware and impact findings.

  8. Route on Final Verdict

    Decision

    Trigger containment for confirmed intrusions.

  9. Isolate Host

    Response action

    Halt the ransomware execution and session abuse.

  10. Analyst Review

    Analyst task

    Verify the agent's findings and document the incident lifecycle.

  11. Close-out

    Analyst task

    Finalize documentation and archive the hunt results.

Coverage

Scenario coverage

StageCoveredHow, or why not
DocuSign Phishing Lure
T1566.002
Yes dns-phishing-lures
M365 Session Hijacking
T1539
Yes m365-auth-anomaly, agent-identity-triage
Malware Dropper Execution
T1204.002
Yes malware-execution
Data Encryption for Impact
T1486
Yes ransomware-impact

Blind spots

  • Needs endpoint agent coverage. A host without an agent could be executing malware undetected even if identity logs show session hijacking. It would answer Are there infected hosts that are not reporting process or file activity?.
  • Needs local browser history and cookie artifacts. This hunt relies on identifying the aftermath (anomalous sign-ins) rather than the direct theft, which may allow stealthy proxy usage to go unnoticed. It would answer Can we confirm the browser-level cookie theft event?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
malware_filenameslist[string]VID001.exe, client32.exe, WCInstaller_NonAdmin.exe, content.js, SECOH-QAD.exeKnown filenames of malicious droppers observed in recent telemetry.
malware_hasheslist[hash]9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507, e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47, c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2, 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55, 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f, a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91SHA256 hashes of malware droppers and tools identified by Talos.
phishing_domainslist[domain]95.sbx.tg, 38d053135d-95.sbx.tg, c4dd71e347-95.sbx.tg, 9f1f11a708-100.sbx.tgDocuSign phishing and sandbox domains observed in the campaign; docusign.net removed to reduce noise.
scope_hostslist[host]—Optional list of hostnames to focus the hunt.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single detection rule on malware hashes is easily bypassed by binary rotation.
  This hunt correlates cloud identity anomalies with host behavior and file impact,
  providing context that a single-surface rule cannot achieve.
blind_spots:
- id: missing-endpoint-visibility
  question: Are there infected hosts that are not reporting process or file activity?
  requires: endpoint agent coverage
  risk: A host without an agent could be executing malware undetected even if identity
    logs show session hijacking.
  stage: execution-malware-droppers
- id: browser-forensic-gap
  question: Can we confirm the browser-level cookie theft event?
  requires: local browser history and cookie artifacts
  risk: This hunt relies on identifying the aftermath (anomalous sign-ins) rather
    than the direct theft, which may allow stealthy proxy usage to go unnoticed.
  stage: credential-access-session-theft
coverage:
- stage: initial-access-docusign-phishing
  status: covered
  steps:
  - dns-phishing-lures
- stage: credential-access-session-theft
  status: covered
  steps:
  - m365-auth-anomaly
  - agent-identity-triage
- stage: execution-malware-droppers
  status: covered
  steps:
  - malware-execution
- stage: impact-data-encryption
  status: covered
  steps:
  - ransomware-impact
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: M365 session hijacking via phishing platforms like NovaCookies bypasses
    traditional MFA. Detecting the subsequent malware execution and ransomware impact
    on the same user context provides a high-confidence signal for containing intrusions.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed
  phishing, enabling them to execute malicious droppers and deploy ransomware across
  the fleet.
labels:
- hunt
- attack.t1566.002
- attack.t1539
- attack.t1204.002
- attack.t1486
name: M365 Session Hijacking and Malware Execution
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  malware_filenames:
    default:
    - VID001.exe
    - client32.exe
    - WCInstaller_NonAdmin.exe
    - content.js
    - SECOH-QAD.exe
    description: Known filenames of malicious droppers observed in recent telemetry.
    from:
      kind: article
      observed: '2026-08-27'
      ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
    type: list[string]
  malware_hashes:
    default:
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47
    - c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2
    - 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    - a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91
    description: SHA256 hashes of malware droppers and tools identified by Talos.
    from:
      kind: article
      observed: '2026-08-27'
      ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
    type: list[hash]
  phishing_domains:
    default:
    - 95.sbx.tg
    - 38d053135d-95.sbx.tg
    - c4dd71e347-95.sbx.tg
    - 9f1f11a708-100.sbx.tg
    description: DocuSign phishing and sandbox domains observed in the campaign; docusign.net
      removed to reduce noise.
    from:
      kind: article
      observed: '2026-08-27'
      ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
    type: list[domain]
  scope_hosts:
    default: []
    description: Optional list of hostnames to focus the hunt.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Prioritize users with access to sensitive document shares and workstations
  in departments commonly receiving DocuSign notifications. Start with a 14-day lookback
  to catch the session theft beachhead.
references:
- name: "\u201CSorry, I can\u2019t help with that\u201D: How your guardrails might\
    \ become the attacker\u2019s best friend"
  url: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
- name: "Talos \u2014 Sorry, I can\u2019t help with that: How your guardrails might\
    \ become the attacker\u2019s best friend"
  url: https://blog.blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
related:
- hunt: m365-token-theft-browser-forensics
  reason: This hunt focuses on network and authentication anomalies; browser-specific
    cookie artifacts require a separate forensic hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: DocuSign Phishing Lure
    observables:
    - genuine docusign notifications
    - docusign.net
    - NovaCookies phishing platform
    slug: initial-access-docusign-phishing
    tactic: initial-access
    techniques:
    - T1566.002
  - name: M365 Session Hijacking
    observables:
    - M365 session theft
    - real-time session hijacking
    - $320/month phishing kit
    slug: credential-access-session-theft
    tactic: credential-access
    techniques:
    - T1539
  - name: Malware Dropper Execution
    observables:
    - VID001.exe
    - client32.exe
    - WCInstaller_NonAdmin.exe
    - content.js
    - SECOH-QAD.exe
    - d4aa3e7010220ad1b458fac17039c274_62_Exe.exe
    - ToxicPanda banking trojan
    slug: execution-malware-droppers
    tactic: execution
    techniques:
    - T1204.002
  - name: Data Encryption for Impact
    observables:
    - ransomware encryption
    - file renaming
    - inaccessible user files
    slug: impact-data-encryption
    tactic: impact
    techniques:
    - T1486
  summary: The NovaCookies campaign uses genuine DocuSign notifications to lure users
    into Microsoft 365 session theft via a subscription-based phishing kit. Stolen
    sessions enable unauthorized access to corporate environments, leading to the
    deployment of various banking trojans and droppers like ToxicPanda or VID001.exe,
    and eventually culminating in data encryption for impact.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
tlp: clear
type: investigation
---


# M365 Session Hijacking and Malware Execution

This hunt follows an attack lifecycle from initial cloud identity theft to endpoint ransomware impact. It begins by identifying suspicious DocuSign-related phishing activity and anomalous M365 sign-ins that suggest session hijacking using the NovaCookies platform. The hunt then pivots to the endpoint to detect the execution of specific malware droppers identified by Talos telemetry and monitors for high-frequency file operations characteristic of data encryption. By correlating cloud authentication anomalies with host-side process and file artifacts, the hunt identifies compromised users and the specific hosts where malicious code established a beachhead.

## scope-windows-workstations
<!-- Scope Windows Workstations -->
Identify active Windows hosts that are the primary targets for phishing and subsequent ransomware execution.

```sqlite target=endpoint role=scoping params=(lookback_days=lookback_days)
~~~yaml
expected: A list of targetable Windows hosts. None means no Windows systems were enrolled
  or active during the window.
reads:
- hostname
- os_name
- os_version
- last_seen
- time
silence: not_evidence_of_absence
source: hb_devices
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT hostname, os_name, os_version, last_seen FROM hb_devices WHERE platform = 'windows' AND lifecycle_state = 'active' AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-parallel
<!-- Early Stage Parallel -->
parallel:
- → dns-phishing-lures
- → m365-auth-anomaly
join: → agent-identity-triage

## dns-phishing-lures
<!-- DNS Phishing Lures -->
Detect resolution of DocuSign-themed phishing sites or sandbox domains named in the report.

```sqlite target=endpoint role=enrichment params=(phishing_domains=phishing_domains, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Hosts resolving malicious domains; silence means no direct connection to
  the reported lures occurred.
reads:
- device_hostname
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, query_hostname, COUNT(*) AS total_lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, query_hostname
```

## m365-auth-anomaly
<!-- M365 Sign-in Anomalies -->
Find successful M365 logons from unusual IP addresses per user, suggesting session hijacking.

```sqlite target=identity role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A rare user/IP combination that differs from historical patterns. A single
  logon from a new IP for a user is a typical hijacking signal.
prevalence:
  by: actor_user_name
  key:
  - src_endpoint_ip
  rare_below: 2
reads:
- actor_user_name
- src_endpoint_ip
- provider
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT actor_user_name, src_endpoint_ip, COUNT(*) AS logon_count, MIN(time) AS first_logon, MAX(time) AS last_logon FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING logon_count < 5 ORDER BY logon_count ASC
```

## agent-identity-triage
<!-- Triage Identity Hijack -->
```agent target=hunter
cite: required
context:
- dns-phishing-lures
- m365-auth-anomaly
max_iterations: 4
objective: Identify users who likely fell for a DocuSign phishing lure and subsequently
  had their M365 session hijacked. Cite the resolved domain and the anomalous logon
  IP.
success_criteria: A list of users with corresponding suspicious IP and DNS evidence.
tools:
- endpoint
- identity
```

## follow-on-parallel
<!-- Endpoint Follow-on Hunt -->
parallel:
- → malware-execution
- → ransomware-impact
join: → follow-on-agent

## malware-execution
<!-- Malware Execution -->
Detect the execution of the specific droppers and tools identified by Talos.

```sqlite target=endpoint role=detection-candidate params=(malware_hashes=malware_hashes, malware_filenames=malware_filenames, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Process executions matching the reported malware. Any match is high confidence.
reads:
- device_hostname
- process_name
- process_hash_sha256
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_hash_sha256, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{malware_filenames}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## ransomware-impact
<!-- Ransomware Impact -->
Detect high-frequency file operations on user document types, characteristic of encryption.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A burst of file creations, deletions, or renames on document files. Silence
  means no mass encryption events were detected on the targeted surfaces.
reads:
- device_hostname
- actor_user_name
- activity_id
- file_path
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, COUNT(*) AS op_count, MIN(time) AS first_op, MAX(time) AS last_op FROM hb_file_activity WHERE activity_id IN (1, 4, 5) AND (LOWER(file_path) LIKE '%.docx' OR LOWER(file_path) LIKE '%.xlsx' OR LOWER(file_path) LIKE '%.pdf') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, actor_user_name HAVING op_count > 20
```

## follow-on-agent
<!-- Final Correlation Agent -->
```agent target=hunter
cite: required
context:
- agent-identity-triage
- malware-execution
- ransomware-impact
max_iterations: 6
objective: Determine if compromised identities from the early stage match users or
  hosts where malware and ransomware impact occurred. Issue a malicious verdict if
  the killchain is confirmed.
success_criteria: A final verdict per host citing the correlation between identity
  theft and malicious endpoint activity.
tools:
- endpoint
- identity
```

## route-decision
<!-- Route on Final Verdict -->
if~: "the follow-on-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-endpoint-visibility)
else: → close-out

## isolate-host
<!-- Isolate Host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the infected host from the network and revoke all M365 session tokens for the affected user account.
```
→ analyst-review

## analyst-review
<!-- Analyst Review -->
```manual target=analyst
Review the correlated evidence: DNS lure resolution, anomalous IP sign-in, and endpoint malware execution. Confirm if the file operations align with a ransomware attack.
```
→ close-out

## close-out
<!-- Close-out -->
```manual target=analyst
Record the hosts and users examined. Note any new phishing domains discovered to update future hunt iterations.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.