Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

August 26, 2026

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

August 26, 2026

Fake Minecraft Clients Deliver WeedHack Malware Despite Takedown

August 25, 2026
Facebook X (Twitter) Instagram
Wednesday, August 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
News

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

Team-CWDBy Team-CWDAugust 24, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A financially motivated threat actor has been observed abusing free Notion accounts, malicious PDFs and device code phishing to harvest authentication tokens from targeted organizations.

Sublime’s Threat Intelligence & Research team, which tracks the actor as Doubloon Dredger, identified the activity in July 2026 after a customer reported abuse of Notion, a digital workspace and collaboration application, and researchers found similar attacks against another organization.

The campaigns used fake accounts impersonating senior executives to send document-sharing notifications from legitimate Notion infrastructure.

Notion Abuse Leads to EvilTokens

The emails told recipients that an executive at their company had shared a document with them. Because the notifications were generated through compromised Notion accounts, they passed DKIM, SPF and DMARC checks, according to Sublime.

Clicking the notification led the recipient to an intermediary PDF. A “Review and Sign” button then redirected the victim to an EvilTokens device code harvesting page disguised as an Adobe Acrobat document-sharing authentication screen.

The page provided a verification code and instructions directing the victim to Microsoft’s legitimate login or device code entry page. If the victim entered the code, EvilTokens could obtain an authorization token and give the attacker access to the account. The platform also provides MailVault, a webmail client that allows attackers to interact with compromised inboxes.

EvilTokens has been available as a phishing-as-a-service (PaaS) platform since at least February 2026, with access sold through a private Telegram channel, Sublime said.

Read more on device code phishing: Russian Hackers Target Microsoft 365 Accounts with Device Code Phishing

Doubloon Dredger Uses Layered Phishing Infrastructure

Sublime identified 14 additional PDFs with the same metadata and overlapping-link construction. Each PDF contained two or three links placed over the same button, meaning different PDF readers could present different destinations.

The researchers assessed with low confidence that this provided infrastructure redundancy or helped complicate defensive analysis.

The PDFs targeted organizations across manufacturing, telecommunications, retail, health and logistics, while some samples linked to Kratos phishing pages rather than EvilTokens. Sublime said it could not determine whether the PDF builder was shared between different actors or used exclusively by Doubloon Dredger.

The researchers also found similarities between the campaign’s first-stage JavaScript and Tycoon2FA device code harvesting activity. Their analysis identified 603 related scripts, with 416 decoding to EvilTokens and 187 to Tycoon2FA. Sublime assessed with moderate confidence that Doubloon Dredger was a customer of both PhaaS platforms.

The findings come months after a global operation disrupted Tycoon2FA, although the platform resumed activity shortly afterward.

Sublime recommended organizations disable device code authentication where possible or restrict device code token generation to trusted devices.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Next Article AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files
Team-CWD
  • Website

Related Posts

News

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

August 26, 2026
News

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

August 26, 2026
News

Fake Minecraft Clients Deliver WeedHack Malware Despite Takedown

August 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to help older family members avoid scams

October 31, 2025

When ‘hacking’ your game becomes a security risk

October 17, 2025

What is it, and how do I get it off my device?

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.