VYPR
researchPublished Aug 24, 2026· 1 source

Doubloon Dredger Malware Abuses Notion to Steal Microsoft Authentication Tokens

A sophisticated malware campaign known as Doubloon Dredger is exploiting Notion's integration features and malicious PDFs to harvest user authentication tokens for Microsoft accounts.

The "Doubloon Dredger" malware campaign has surfaced with a novel attack vector that leverages the popular productivity tool Notion to pilfer sensitive authentication tokens from Microsoft accounts. This campaign employs a multi-stage approach, beginning with the distribution of malicious PDF files designed to deceive unsuspecting users.

Upon opening these malicious PDFs, victims are prompted to grant permissions, often disguised as a necessary step for viewing content or accessing a required resource. The attackers have ingeniously integrated malicious links or embedded scripts within these PDFs that, when activated, lead users to a compromised or attacker-controlled environment. This environment is designed to trick users into authorizing access to their Microsoft accounts.

The core of the attack lies in the abuse of OAuth, a widely used authorization framework. Threat actors trick users into granting their malicious applications or services access to their Microsoft accounts via OAuth consent screens. Once a user grants this permission, the attacker can obtain OAuth tokens, which act as digital keys, allowing them to access the user's account without needing their password.

What makes this campaign particularly concerning is its use of Notion's integration capabilities. Attackers are reportedly using Notion to host or facilitate the exfiltration of these harvested OAuth tokens. By integrating with Notion, the malware can potentially blend in with legitimate activity or leverage Notion's infrastructure for command-and-control or data staging, making detection more challenging.

The impact of this technique is significant. Stolen OAuth tokens can grant attackers persistent access to a victim's Microsoft account, enabling them to read emails, access files stored in OneDrive, manage calendar events, and potentially impersonate the user in communications. This level of access can be leveraged for further phishing attacks, corporate espionage, or to gain a foothold within an organization's network.

While specific details on the scale of the Doubloon Dredger campaign and the exact methods of Notion integration are still emerging, the campaign highlights a growing trend of threat actors creatively misusing legitimate cloud services and productivity tools to achieve their malicious objectives. This tactic bypasses traditional security measures that might focus solely on detecting malware signatures or network traffic anomalies.

Security researchers are advising users to exercise extreme caution when opening PDF attachments from unknown sources and to be vigilant about the permissions they grant to applications, especially when authorizing access to cloud services like Microsoft 365. Reviewing active application permissions regularly and revoking access for any suspicious or unused services is a critical mitigation step.

This campaign underscores the evolving landscape of cyber threats, where attackers are becoming increasingly adept at social engineering and exploiting the interconnectedness of modern digital workflows. The abuse of tools like Notion demonstrates the need for continuous adaptation in security strategies to account for these novel attack vectors.

Synthesized by Vypr AI