Mr Brean is a threat actor name used in extortion communications tied to the 2026 compromise of the market intelligence platform Klue and the subsequent theft of customer Salesforce data. The persona is assessed with high confidence to be associated with, or a front for, the extortion group Icarus, which emerged in 2026. In the Klue incident, the operators conducted a supply-chain intrusion by accessing Klue backend servers, executing unauthorized commands, deploying malicious code to harvest OAuth tokens from customer integrations, and then abusing the Salesforce REST API to extract CRM data from affected downstream organizations. Reported victim impact was limited to business data held in Salesforce-connected environments rather than compromise of the victims' internal networks. The actor's observed tradecraft in this operation includes initial access through a third-party platform compromise, theft of authentication material, post-exploitation activity within cloud-integrated business applications, and large-scale data exfiltration followed by attempted extortion. The available evidence directly links the Mr Brean persona to extortion activity and to infrastructure or identifiers associated with Icarus. No high-confidence attribution to a nation state is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.