A financial threat actor, identified as 'Doubloon Dredger,' has been exploiting free Notion accounts and malicious PDFs to harvest authentication tokens from organizations. The campaign, uncovered by Sublime's Threat Intelligence team, involves fake accounts mimicking senior executives to send convincing document-sharing notifications that pass email verification checks.
Victims are directed to a phishing page disguised as an Adobe document where entering a verification code gives the attacker access to their accounts. The 'EvilTokens' platform, which offers phishing-as-a-service, has been linked to this activity. Sublime recommends disabling device code authentication where possible to mitigate risks.