Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
ID: 95f2ee64-eaab-59d6-8185-cd78fbb1d630
STIX ID: report--95f2ee64-eaab-59d6-8185-cd78fbb1d630
Feed Name: Infosecurity Magazine (News)
Sublime's Threat Intelligence team observed Doubloon Dredger abusing compromised Notion accounts to send legitimate-looking document notifications that lead to intermediary PDFs and device-code phishing pages (EvilTokens/Tycoon2FA) which harvest Microsoft authentication tokens and allow attackers to access inboxes; researchers identified hundreds of related scripts and PDF samples across multiple industries and advised disabling or restricting device-code authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
