logo

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

ID: 95f2ee64-eaab-59d6-8185-cd78fbb1d630

STIX ID: report--95f2ee64-eaab-59d6-8185-cd78fbb1d630

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

...
...

Sublime's Threat Intelligence team observed Doubloon Dredger abusing compromised Notion accounts to send legitimate-looking document notifications that lead to intermediary PDFs and device-code phishing pages (EvilTokens/Tycoon2FA) which harvest Microsoft authentication tokens and allow attackers to access inboxes; researchers identified hundreds of related scripts and PDF samples across multiple industries and advised disabling or restricting device-code authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.