icarus
Icarus is an emerging extortion-focused cybercrime threat group first appearing in April 2026. Based on the provided reporting, Huntress assessed with high confidence that Icarus was responsible for the compromise of Klue and the resulting supply chain attack that enabled theft of Salesforce CRM data from multiple organizations. The actor is identified in the content as distinct from ShinyHunters, although the intrusion pattern resembled earlier third-party Salesforce integration abuse seen in prior campaigns. In the Klue incident, attackers compromised Klue backend systems, reportedly using a long-disused but still active credential created for a prototype third-party integration. They then pushed malicious code to collect customer OAuth tokens, pivoted through Klue infrastructure, and used stolen OAuth credentials and a compromised Klue integration service account to access customer Salesforce environments directly. Reported activity included reconnaissance against Salesforce REST API endpoints such as /services/data/v59.0/sobjects and bulk exfiltration via /services/data/v59.0/query, using automated Python scripts over roughly 24 hours, including bursts of nearly 1,000 queries in 15 minutes. Huntress also observed malicious requests with blank User-Agent values, "5238," and Python-urllib strings. The group’s targeting in this reporting centered on organizations using Klue integrations, with stolen data including Salesforce CRM and related business information such as contacts, sales communications, price quotes, competitive intelligence reports, account data, and in some cases Gong data. The campaign involved extortion emails sent to affected organizations. The actor used the alias "mr bean" in ransom communications and directed victims to negotiate via Session Messenger. Huntress linked the activity to Icarus by matching Session Messenger IDs in extortion emails to IDs published on the group’s dark web leak site. The leak site was described as new, with teaser posts such as "Get Ready" and statements that "big corps" would be listed soon. The content also states that extortion emails were sent through compromised mail infrastructure belonging to subsidiaries of Australian retailer Global Retail Brands. Known alias directly mentioned in the content: "mr bean" (used in extortion emails).
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
Tradecraft
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting an extortion campaign following the Klue OAuth breach by stealing Salesforce CRM data from multiple organizations and sending extortion emails tied to its leak site and Session Messenger contact.
Extortion-focused actor linked to the Klue supply chain compromise. The actor compromised Klue backend systems, stole OAuth tokens, used those tokens to access customer CRM platforms such as Salesforce and Gong, exfiltrated data, and sent extortion emails while advertising leaks via a dark web site and gofile.io.
Conducting extortion tied to stolen Salesforce data obtained via the Klue third-party integration compromise; using a dark web leak site and ransom-style outreach to victims.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.