HomeRisk ManagementsDoubloon Dredger Exploits Notion to Extract Authentication Tokens

Doubloon Dredger Exploits Notion to Extract Authentication Tokens

Published on

spot_img

In a recent development within the cybersecurity landscape, a financially motivated threat actor has been identified exploiting free Notion accounts alongside malicious PDFs and device code phishing strategies to extract authentication tokens from specific organizations. This alarming trend was brought to light by Sublime’s Threat Intelligence & Research team, who have assigned the alias “Doubloon Dredger” to this threat actor.

The investigation into these activities commenced in July 2026, following a customer report of suspicious behavior concerning Notion, a widely used digital workspace and collaboration tool. Upon further scrutiny, Sublime’s researchers discovered that similar tactics were being employed against another organization, showcasing the actor’s broader operational scope.

### Exploiting Notion Accounts

The deception employed by Doubloon Dredger involved the use of fake accounts masquerading as senior executives within organizations. These accounts sent out notifications for document sharing through legitimate Notion infrastructure, which made the emails appear credible. The notifications were designed to compel recipients into opening them, as they were engineered to indicate that a company executive had shared a vital document.

Because the notifications stemmed from compromised accounts, they successfully passed DKIM, SPF, and DMARC checks, which are technical methods used to combat email spoofing and ensure the authenticity of the message. This further heightened the likelihood that recipients would engage with the content without suspicion.

Upon clicking the notification, victims were redirected to an intermediary PDF. Within this document, a “Review and Sign” button was embedded, which directed the unfortunate recipient to a phishing page labeled as an “Adobe Acrobat document-sharing authentication screen.” This page was part of the broader EvilTokens initiative designed to harvest device codes.

### The Mechanics of EvilTokens

The phishing page provided victims with a verification code along with detailed instructions directing them to Microsoft’s official login or device code entry screen. If the victim unwittingly entered the code on the phishing page, EvilTokens could capture the authorization token, thereby granting the attacker unrestricted access to the account. The platform additionally features MailVault, a webmail client that empowers attackers to interact with compromised inboxes seamlessly, allowing for an escalation of malicious activities.

EvilTokens has been active as a phishing-as-a-service (PaaS) platform since at least February 2026, with subscriptions being traded via a discreet Telegram channel, according to Sublime’s findings. This model effectively lowers the barrier of entry for cybercriminals, enabling them to execute sophisticated attacks without extensive technical knowledge.

### A Complex Infrastructure of Phishing

Doubloon Dredger’s campaigns manifested a layered approach to phishing, with Sublime identifying 14 additional PDFs that shared the same metadata and contained linked elements. Each PDF featured two or three links aligned over the same button, a tactical decision that ensured different PDF readers could yield disparate destinations depending on the software used to open them. This tactic aimed to create redundancy within the infrastructure or possibly to obfuscate detection efforts by cybersecurity professionals.

The targeted organizations included a diverse array of sectors such as manufacturing, telecommunications, retail, health, and logistics. Interestingly, some of the analyzed samples pointed towards Kratos phishing pages rather than EvilTokens, leaving open the question of whether the PDF creation tool was a shared resource among various malicious actors or solely used by Doubloon Dredger.

In addition, the researchers observed notable similarities between the initial stage JavaScript employed in these campaigns and that used in Tycoon2FA’s device code harvesting activities. Their analysis uncovered 603 related scripts, with 416 correlating with EvilTokens and 187 relating to Tycoon2FA. This finding leads to a moderate level of confidence that Doubloon Dredger may be utilizing the services offered by both phishing-as-a-service platforms.

### Recommendations for Organizations

These findings arise shortly after a worldwide operation succeeded in disrupting the Tycoon2FA infrastructure; however, the service resumed activities almost immediately. In light of these developments, Sublime has urged organizations to take precautionary measures. Recommendations include disabling device code authentication wherever feasible and restricting device code token generation to trusted devices only. Such proactive measures could significantly mitigate the risk associated with these sophisticated phishing attacks and protect sensitive organizational data from malicious exploitation.

As this threat landscape continues to evolve, vigilance and proactive security measures will be paramount for organizations to guard against these sophisticated cyber threats.

Source link

Latest articles

New Guidance Assists Businesses in Verifying Quantum-Safe Hardware Claims

In an era marked by the rapid advancement of quantum computing, organizations are increasingly...

Google and Bing Search Results Revealed Covert Banking Phishing Pages

Threat actors are increasingly exploiting Google and Bing as conduits for phishing attacks, leveraging...

Windows Defender Driver Can Leave Systems Vulnerable

In recent developments within cybersecurity, experts have uncovered alarming techniques utilized by malicious actors...

AI Agents Engaging in Unauthorized Activities During Cyber Testing

The UK’s AI Security Institute (AISI) has recently revealed a concerning security incident involving...

More like this

New Guidance Assists Businesses in Verifying Quantum-Safe Hardware Claims

In an era marked by the rapid advancement of quantum computing, organizations are increasingly...

Google and Bing Search Results Revealed Covert Banking Phishing Pages

Threat actors are increasingly exploiting Google and Bing as conduits for phishing attacks, leveraging...

Windows Defender Driver Can Leave Systems Vulnerable

In recent developments within cybersecurity, experts have uncovered alarming techniques utilized by malicious actors...