Doubloon Dredger abuses Notion to harvest tokens
📄 Sublime's Threat Intelligence team identified a financially motivated actor, tracked as Doubloon Dredger, abusing free Notion accounts and malicious PDFs in July 2026 to harvest authentication tokens. Fake notifications from compromised Notion accounts bypassed DKIM/SPF/DMARC checks and steered victims to intermediary PDFs that redirected to an EvilTokens device-code phishing page. If users entered the provided code on Microsoft's legitimate device-code entry, attackers obtained authorization tokens and could access accounts and inboxes via tools like MailVault.
