Skip to main content
Threat IntelligenceEmerging Threats

Notion Abused to Harvest Authentication Tokens in Targeted Attacks

Blurred laptop and smartphone screens on a quiet office desk, suggesting a secure login page.

603 related scripts were identified; 416 decoded to EvilTokens and 187 to Tycoon2FA, a single metric that ties a layered phishing campaign to two phishing-as-a-service platforms and a wider abuse of legitimate collaboration infrastructure.

Notion abuse and the initial discovery

Sublime's Threat Intelligence & Research team, which tracks the actor as Doubloon Dredger, identified activity in July 2026 after a customer reported abuse of Notion, the digital workspace and collaboration application. Researchers found similar attacks against another organization and traced the campaigns to free Notion accounts that impersonated senior executives and sent document‑sharing notifications from legitimate Notion infrastructure.

Because the notifications were generated through compromised Notion accounts, Sublime said they passed DKIM, SPF and DMARC checks — meaning standard email authentication signals did not flag the messages as fraudulent.

How EvilTokens harvests device authentication codes

The phishing chain Sublime described began with a Notion notification that led recipients to an intermediary PDF. A conspicuous “Review and Sign” button in that PDF redirected victims to an EvilTokens device‑code harvesting page disguised as an Adobe Acrobat document‑sharing authentication screen.

The page presented a verification code and instructions that directed the victim to Microsoft's legitimate login or device code entry page. If the victim entered the code, Sublime reported, EvilTokens could obtain an authorization token and give the attacker access to the account. The platform also provides MailVault, a webmail client that allows attackers to interact with compromised inboxes.

Layered PDFs and overlapping link construction

Sublime identified 14 additional PDFs with the same metadata and overlapping‑link construction. Each PDF contained two or three links placed over the same button so that different PDF readers could present different destinations. Researchers assessed with low confidence that the technique provided infrastructure redundancy or helped complicate defensive analysis.

Targets spanned multiple sectors: manufacturing, telecommunications, retail, health and logistics. Some PDF samples, Sublime said, linked to Kratos phishing pages rather than EvilTokens. The researchers could not determine whether the PDF builder was a shared tool used by multiple actors or a capability exclusive to Doubloon Dredger.

Connections to EvilTokens and Tycoon2FA phishing-as-a-service

Sublime's analysis found similarities between the campaign's first‑stage JavaScript and Tycoon2FA device‑code harvesting activity. In total the team identified 603 related scripts; 416 decoded to EvilTokens and 187 to Tycoon2FA. Based on that dataset, Sublime assessed with moderate confidence that Doubloon Dredger was a customer of both PhaaS platforms.

Those findings follow a broader disruption: Sublime noted the activity comes months after a global operation disrupted Tycoon2FA, though the platform resumed activity shortly afterward. Separately, Sublime reported EvilTokens has been available as a phishing‑as‑a‑service platform since at least February 2026, with access sold through a private Telegram channel.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: Sublime recommended disabling device‑code authentication where possible or restricting device‑code token generation to trusted devices. The campaign shows device‑code flows and legitimate service redirects can be abused even when email authentication checks pass.
  • Affected enterprises and procurement leaders: Organizations using shared collaboration tools — including free accounts on platforms such as Notion — should monitor for account compromise and review third‑party access to document‑sharing notifications, since compromised accounts can generate messages that pass DKIM, SPF and DMARC checks.
  • End users and employees: Recipients should be aware that a legitimate‑looking notification from a collaboration service can still lead to a malicious device‑code prompt that leverages genuine vendor login pages; entering a displayed verification code can hand over an authorization token to attackers.

The campaign Sullivan documented underscores a convergence of three things: legitimate collaboration infrastructure abused to deliver phishing lures, intermediary PDF tricks that change destinations based on the viewer, and commercially available phishing services that harvest device‑code tokens and offer inbox access via tools like MailVault. Sublime's concrete recommendation — disable or tightly restrict device‑code authentication where feasible — is a targeted mitigation rooted in how these attacks operate.

Source: https://www.infosecurity-magazine.com/news/doubloon-dredger-notion/