www.infosecurity-magazine.com 8/24/2026, 1:20:42 PM · external

Doubloon Dredger uses malicious PDFs to steal Notion tokens

Doubloon Dredger uses malicious PDFs to steal Notion tokens
CyberSIXT Evidence Panel
Primary Source sublime.security
Threat Actor
Doubloon Dredger

A financial threat actor, identified as 'Doubloon Dredger,' has been exploiting free Notion accounts and malicious PDFs to harvest authentication tokens from organizations. The campaign, uncovered by Sublime's Threat Intelligence team, involves fake accounts mimicking senior executives to send convincing document-sharing notifications that pass email verification checks.

Victims are directed to a phishing page disguised as an Adobe document where entering a verification code gives the attacker access to their accounts. The 'EvilTokens' platform, which offers phishing-as-a-service, has been linked to this activity. Sublime recommends disabling device code authentication where possible to mitigate risks.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT