A financially motivated threat actor has been observed abusing free Notion accounts, malicious PDFs and device code phishing to harvest authentication tokens from targeted organizations.
Sublime's Threat Intelligence & Research team, which tracks the actor as Doubloon Dredger, identified the activity in July 2026 after a customer reported abuse of Notion, a digital workspace and collaboration application, and researchers found similar attacks against another organization.
The campaigns used fake accounts impersonating senior executives to send document-sharing notifications from legitimate Notion infrastructure.
Notion Abuse Leads to EvilTokens
The emails told recipients that an executive at their company had shared a document with them. Because the notifications were generated through compromised Notion accounts, they passed DKIM, SPF and DMARC checks, according to Sublime.
Clicking the notification led the recipient to an intermediary PDF. A “Review and Sign” button then redirected the victim to an EvilTokens device code harvesting page disguised as an Adobe Acrobat document-sharing authentication screen.
The page provided a verification code and instructions directing the victim to Microsoft's legitimate login or device code entry page. If the victim entered the code, EvilTokens could obtain an authorization token and give the attacker access to the account. The platform also provides MailVault, a webmail client that allows attackers to interact with compromised inboxes.
EvilTokens has been available as a phishing-as-a-service (PaaS) platform since at least February 2026, with access sold through a private Telegram channel, Sublime said.
Doubloon Dredger Uses Layered Phishing Infrastructure
Sublime identified 14 additional PDFs with the same metadata and overlapping-link construction. Each PDF contained two or three links placed over the same button, meaning different PDF readers could present different destinations.
The researchers assessed with low confidence that this provided infrastructure redundancy or helped complicate defensive analysis.
The PDFs targeted organizations across manufacturing, telecommunications, retail, health and logistics, while some samples linked to Kratos phishing pages rather than EvilTokens. Sublime said it could not determine whether the PDF builder was shared between different actors or used exclusively by Doubloon Dredger.
The researchers also found similarities between the campaign's first-stage JavaScript and Tycoon2FA device code harvesting activity. Their analysis identified 603 related scripts, with 416 decoding to EvilTokens and 187 to Tycoon2FA. Sublime assessed with moderate confidence that Doubloon Dredger was a customer of both PhaaS platforms.
The findings come months after a global operation disrupted Tycoon2FA, although the platform resumed activity shortly afterward.
Sublime recommended organizations disable device code authentication where possible or restrict device code token generation to trusted devices.
