Icarus is a cyber-extortion group first publicly identified in June 2026. It is associated with a supply-chain compromise of Klue, a Canadian SaaS competitive-intelligence provider, through a long-unused legacy integration credential. The group inserted malicious code into Klue’s integration environment to harvest OAuth access and refresh tokens associated with customer SaaS integrations. It then used valid tokens to impersonate the trusted Klue integration and access connected Salesforce environments, conducting large-scale API-based exports of CRM information without separately compromising each downstream organization. The Klue operation affected organizations in the technology and cybersecurity sectors, including Huntress, Recorded Future, Tanium, Jamf, HackerOne, Snyk, LastPass, BeyondTrust, and others. Stolen material included business contacts, sales activity, proposals, quotes, pricing, contract details, renewal information, and communications. Icarus used stolen data to extort both Klue and affected customers, publishing victim claims through a leak site and threatening disclosure when deadlines were not met. Reporting also links the group to victim claims involving U.S.-based business-services, technology, and financial-services organizations. Icarus is principally characterized as a data-theft extortion operation. There is no high-confidence evidence that it deployed an encryptor during the Klue campaign. Some reporting associated the extortion activity with the broader ShinyHunters ecosystem, including competing public claims of responsibility, but Icarus’s identity, membership, and relationship to ShinyHunters remain unconfirmed. Its country of origin is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised Klue in a data-extortion incident in which payment reportedly did not prevent continued exposure of victim information.
Ransomware/extortion group claiming responsibility for the Klue supply-chain-style compromise, using stolen OAuth tokens from Klue integrations to access customer Salesforce environments and extort both Klue and affected clients.
Relatively new ransomware/extortion group described as conducting a SaaS supply chain compromise of Klue, exfiltrating sensitive CRM data and contributing to ongoing extortion risk even after ransom payment.
Conducted a supply chain attack against Klue by compromising a legacy integration credential, deploying malicious code to harvest OAuth tokens, and using those tokens to access multiple customer Salesforce environments for large-scale data export.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.