In July 2026, a Sublime customer reached out about having observed Notion abuse for the purpose of delivering phishing attacks. In parallel, Sublime Threat Intelligence & Research (STIR) had identified similar phishing activity directed at another customer in a similar vertical. In these attacks, the threat actor abuses Notion by creating a fake account and then invites targets to view a PDF that contains a malicious link. The payload link then takes the target to an EvilTokens device code harvesting page.
While phishing and token harvesting are common, the threat actor chained together several uncommon tactics for this novel attack:
- They abuse Notion to gain access to a legitimate email sender, reputable infrastructure, and a place to host a malicious PDF.
- They use a PDF builder that includes two to three overlapping links, attempting to evade defensive tooling and detections while potentially increasing the shelf life of any single malicious PDF with redundant infrastructure.
- The payload landing page uses a JavaScript obfuscation and encryption technique similar to recent Tycoon2FA device code harvesting campaigns.
STIR is tracking this threat actor as DOUBLOON DREDGER. They are an eCrime-oriented threat actor whose tradecraft is characterized by similar first-stage JavaScript usage, specific PDF kit builder, re-used infrastructure, and the device code token theft activity.
As a result of our investigation, we have released a Core Feed coverage update for all Sublime users to identify malicious emails abusing Notion’s service and trust via executive impersonation. In this post, we will take a look at the investigation.
Attack overview
In these attacks, DOUBLOON DREDGER creates Notion accounts impersonating high-level executives. They then use these accounts to send document share notifications to targets working at the same company as the impersonated executive. Because Notion is a legitimate business and service, these notifications from free accounts pass DKIM, SPF, and DMARC.
The target then receives a notification email indicating a document has been shared with them by the executive. VIP impersonation is a very common tactic used to increase urgency. In fact, our research showed that nearly 20% of BEC attacks in 2025 showed significant elements of impersonation
Here’s an example attack email:

When the target clicks the Get started button, they’re taken to an intermediary PDF.

When the target clicks the Review and Sign button, they’re taken to an EvilToken harvesting site that impersonates an Adobe Acrobat document sharing authentication page. They’re given a “verification code” and a set of steps they need to follow to get access to the “document” shared with them by the “executive” at their company. The linked button takes them to the real Microsoft login or device code entry page.

If the target copies the code and follows the steps, EvilTokens harvests their authorization token, granting the attacker access to the target’s account. Once an account has been compromised, EvilTokens also provides the attacker with another tool called MailVault. MailVault is a web mail client which allows threat actors to interact with the inboxes of the victims.
More on EvilTokens
EvilTokens is a device code token harvesting platform that was first observed in February 2026. It rapidly gained traction in the eCrime marketplace where access was sold via its private Telegram channel. Public reporting indicates EvilTokens administrators provide a high level of customer support and tooling to enable their customers to conduct phishing attacks, token theft, and follow-on actions such as business email compromise (BEC) attacks or follow-up phishing operations.
PDF build kit for phishing
With further investigation, we identified 14 additional similar PDFs via a third-party malware repository (two samples led to Kratos Phishing-as-a-Service (PhaaS) attacks). These samples indicate the PDF was created using a custom build kit and that it appears to only be used for directing targets to varying phishing kit/PhaaS landing pages.
The PDFs all contained the same metadata and used the same overlapping link overlay technique where the links overlap at exactly the same or very close coordinates across different PDFs and infrastructure.
Here’s another version of the malicious PDF and how its overlapping links render:

With this overlapping, the target is unwittingly presented with one of three links via the Review and Sign button. Which link is presented to the user is dependent upon the PDF reader and how that reader renders links. Based on this variable behavior, it appears that defensive analysis tools may interpret these links, visit, and present them differently. We have assessed with low confidence that the threat actors were motivated to use this technique in order to build infrastructure redundancy into their operations.
PDF variability code
Below is the code used in the PDF to create the variable links. The first code block shows the URI link objects being defined. The second shows the overlapping rectangular coordinates for each link.
URI Link objects being defined in malicious PDF
Rectangle objects being defined
This table makes it easier to visualize the overlapping elements. Reference the table above for the full attack URI:
Attack variations
We’ve identified links to both EvilTokens and Kratos credential harvesting pages within the malicious PDFs. Due to visibility limitations, we cannot determine if the PDF builder tool is shared among different actors or used exclusively by DOUBLOON DREDGER.
The PDF filenames included the company names of the likely intended targets. These filenames indicated a variety of verticals were targeted, as is common in financially motivated operations. Here are the targeted industries and frequencies from those 14 PDFs:
Attack infrastructure
The threat actors used Cloudflare Workers, AWS, and custom domains hosted on varying providers’ infrastructure to deliver device code harvesting pages to their targets. Almost all of the PDFs included the following two URLs:
STIR has assessed with low confidence that this re-used infrastructure indicates that DOUBLOON DREDGER is using multiple device code token PhaaS kits during the same campaign. A higher confidence assessment is precluded by the alternate hypothesis that the links could simply be artifacts of the PDF builder itself.
The below table provides a list of domains extracted from the PDFs, as well which phishing kit they are associated with when known.
Device code harvesting and Tycoon2FA overlap
We’ve identified that the initial JavaScript used to load this EvilTokens campaign’s device code harvesting page is similar to a recent Tycoon2FA device code harvesting campaign that we investigated a few months back. Approximately 603 first-stage scripts were identified in a third-party malware repository dating from December 2025 to the present. Of these files, 416 decoded to EvilTokens and the remaining 187 decoded to Tycoon2FA.
We assess with low confidence that a single threat actor or group has purchased access to both EvilTokens and Tycoon2FA and is using their own custom first stage JavaScript in front of those PhaaS kits. Here are the similarities and differences in the first-stage Javascript implementation between the two PhaaS payloads.
Truncated, formatted, and commented examples of each loader script are shown below:
Tycoon2FA
EvilTokens
STIR assessment
STIR tracks this actor and their operations as DOUBLOON DREDGER, which is eCrime-oriented and whose tradecraft is characterized by:
- Similar first-stage JavaScript usage
- PDF kit builder
- Re-used infrastructure
- Device code token theft activity
We’ve also assessed with moderate confidence that DOUBLOON DREDGER is a customer of both EvilTokens and Tycoon2FA device code token PhaaS kits. This assessment is based on the similar first-stage JavaScript, PDF kit usage coupled with overlapping infrastructure, and overall device code token theft operations.
This attack highlights the recent evolution of larger scale device code token theft by financially motivated threat actors. Financially motivated actors continue to use a diverse toolset and adapt in the face of evolving security controls, defenses, and legal actions taken against them. Based on the growing availability of device PhaaS kits like EvilTokens and Tycoon2FA, we have high confidence that device code token theft will continue to be used by criminal threat actors.
The Sublime Threat Intelligence & Research team recommends defenders adhere to the latest guidance around device code security (such as from major vendors), specifically, disabling it or limiting device code token generation from only trusted devices.
To see how Sublime can detect and prevent harvesting attacks like this, get a live platform demo.
Get the latest
Sublime releases, detections, blogs, events, and more directly to your inbox.





.png)
.avif)