Icarus is a criminal extortion and ransomware actor that emerged publicly in 2026 and is best known for a supply-chain compromise of Klue, a SaaS market-intelligence platform. In that intrusion, the group used a long-unused but still-active service or integration credential to access Klue’s environment, deployed code to harvest customer OAuth tokens, and then abused Klue’s trusted integrations to access downstream customer SaaS environments, especially Salesforce and Gong. Rather than breaching each victim individually, Icarus leveraged inherited permissions from third-party integrations to query customer CRM environments directly and exfiltrate business data at scale, including contacts, pricing, quotes, contracts, sales communications, renewal information, and account records. The Klue incident established Icarus as a notable example of data-theft-led supply-chain extortion focused on identity and SaaS trust relationships. Reported downstream victims included multiple technology and cybersecurity companies such as Huntress, Recorded Future, Tanium, Jamf, LastPass, Snyk, HackerOne, OneTrust, BeyondTrust, Gong, Sprout Social, and others. The actor subsequently used leak-site and direct-contact extortion tactics, including deadlines for victim response and threats to publish stolen data. Reporting also places Icarus among the groups contributing to the broader 2026 shift toward data-only extortion without necessarily relying on encryption. Observed tradecraft includes abuse of valid accounts and dormant credentials for initial access, theft of OAuth tokens and session-like delegated access, direct API-based collection from SaaS platforms, large-scale data exfiltration, and post-compromise extortion. The actor’s operations demonstrate emphasis on trusted third-party access paths, cloud application integrations, and downstream compromise through vendor relationships rather than conventional endpoint-centric intrusion alone. Public reporting also notes overlap in attribution discussions with the ShinyHunters extortion ecosystem, but the most consistently referenced operational name for the Klue activity is Icarus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Relatively new ransomware/extortion group described as conducting a SaaS supply chain compromise of Klue, exfiltrating sensitive CRM data and contributing to ongoing extortion risk even after ransom payment.
Conducted a supply chain attack against Klue by compromising a legacy integration credential, deploying malicious code to harvest OAuth tokens, and using those tokens to access multiple customer Salesforce environments for large-scale data export.
Conducted a SaaS supply-chain breach against Klue by abusing an unused service account credential, harvesting OAuth tokens, and using inherited trust to query Salesforce APIs and exfiltrate customer CRM data.
Data-extortion actor that used an expired Klue credential to exfiltrate Salesforce CRM data via OAuth; also cited in the rise of data-only extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.