DOUBLOON DREDGER Abuses Notion Notifications to Steal Auth Tokens
Hackers have found a way to weaponize ordinary Notion notifications to steal employee credentials. The group DOUBLOON DREDGER creates fake executive accounts, sends out document-sharing invitations, and routes victims through a chain of PDF files leading to a page where authentication tokens are ultimately stolen.
A Convincing Campaign Discovered in July 2026
Researchers at Sublime Security uncovered the campaign in July 2026. Attackers registered free Notion accounts under the names of company executives and sent employees notifications about a supposedly shared document. The emails appeared highly credible, since they arrived through Notion’s legitimate service and passed DKIM, SPF, and DMARC checks without issue.
A Multi-Stage Redirect Chain Through Layered PDFs
Clicking the “Get Started” button led the recipient to an intermediary PDF document. The file contained several overlapping links stacked on top of one another – a technique that helped the material evade security filters and extended its useful lifespan before detection. From there, victims were redirected to a fake login page connected to the EvilTokens platform.
EvilTokens: Harvesting Tokens Through Device Code Flow
EvilTokens operates by stealing tokens through a device-code authentication scheme. The victim is shown a verification code alongside instructions to open a genuine Microsoft login page to confirm their identity. If the victim enters the code and follows the provided steps, attackers obtain a valid authorization token – allowing them to log into the account without ever needing the password again.
From Account Takeover to Mailbox Access via MailVault
Once an account is compromised, attackers gain access to an additional tool called MailVault, which lets them operate directly within the victim’s mailbox. This level of access opens the door to further attacks against corporate correspondence, including payment fraud and fresh rounds of phishing emails sent from the compromised account.
Linked to the Tycoon2FA and EvilTokens Ecosystem
Researchers connected DOUBLOON DREDGER to the Tycoon2FA and EvilTokens services. Both tools are offered as criminal services for hire and are designed to bypass multi-factor authentication by stealing valid, active session tokens directly.
Evidence of a Widely Shared Document-Building Toolkit
During its analysis of the campaign, Sublime Security identified 14 additional similar PDF files. Some samples were paired with entirely different phishing kits, including Kratos, suggesting that the underlying document-building toolkit is being used broadly across the threat landscape. It remains unclear at this stage whether the PDF-generation tool belongs to a single group or is shared among multiple independent operators.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.