Breaking
Cyber CrimeDeveloping Story

Notion, PDFs, and PaaS: Token Theft's New Shape

Threat actor Doubloon Dredger exploits Notion and device codes to steal authentication tokens, researchers say.

··2 hours ago·2 min read
smartphone screen showing facebook application
Photo by Justin Morgan on Unsplash

Attackers are always on the lookout for new ways to get past email filters. One group appears to have found a route: abusing legitimate Notion accounts to send phishing emails that pass authentication checks, according to a cybersecurity firm's analysis.

Notion Abused for Credential Harvesting

Sublime's Threat Intelligence & Research team, which tracks the actor as Doubloon Dredger, identified the activity in July 2026 after a customer reported abuse of Notion, a digital workspace and collaboration application, and researchers found similar attacks against another organization. The campaigns used fake accounts impersonating senior executives to send document-sharing notifications from legitimate Notion infrastructure.

The emails told recipients that an executive at their company had shared a document with them. Because the notifications were generated through compromised Notion accounts, they passed DKIM, SPF and DMARC checks, according to Sublime.

EvilTokens Device Code Phishing

Clicking the notification led the recipient to an intermediary PDF. A “Review and Sign” button then redirected the victim to an EvilTokens device code harvesting page disguised as an Adobe Acrobat document-sharing authentication screen. The page provided a verification code and instructions directing the victim to Microsoft's legitimate login or device code entry page. If the victim entered the code, EvilTokens could obtain an authorization token and give the attacker access to the account.

The platform also provides MailVault, a webmail client that allows attackers to interact with compromised inboxes. EvilTokens has been available as a phishing-as-a-service (PaaS) platform since at least February 2026, with access sold through a private Telegram channel, Sublime said.

Layered Phishing Infrastructure

Sublime identified 14 additional PDFs with the same metadata and overlapping-link construction. Each PDF contained two or three links placed over the same button, meaning different PDF readers could present different destinations. The researchers assessed with low confidence that this provided infrastructure redundancy or helped complicate defensive analysis.

The PDFs targeted organizations across manufacturing, telecommunications, retail, health and logistics, while some samples linked to Kratos phishing pages rather than EvilTokens. Sublime said it could not determine whether the PDF builder was shared between different actors or used exclusively by Doubloon Dredger.

Links to Tycoon2FA

The researchers also found similarities between the campaign's first-stage JavaScript and Tycoon2FA device code harvesting activity. Their analysis identified 603 related scripts, with 416 decoding to EvilTokens and 187 to Tycoon2FA. Sublime assessed with moderate confidence that Doubloon Dredger was a customer of both PhaaS platforms.

The findings come months after a global operation disrupted Tycoon2FA, although the platform resumed activity shortly afterward.

Key Statistics

  • 14 additional PDFs with the same metadata and overlapping-link construction
  • 603 related scripts identified, with 416 decoding to EvilTokens and 187 to Tycoon2FA
  • EvilTokens available as a PaaS since at least February 2026

Mitigation and Recommendations

Sublime recommended organizations disable device code authentication where possible or restrict device code token generation to trusted devices.

Why This Matters for Your Organization

This campaign shows how attackers blend legitimate services and newer phishing methods to bypass standard security measures. The abuse of Notion's infrastructure makes these emails harder to spot, while device code phishing targets a gap in many organizations' defenses. For most businesses, the takeaway is clear: reviewing device code settings and limiting token generation to trusted devices could help close a door that attackers are actively exploiting.

#phishing#notion#device-code#eviltokens#tycoon2fa

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories