Icarus is a data-extortion and ransomware-branded threat actor that emerged publicly in 2026 and is most notably associated with the Klue supply-chain breach and subsequent extortion of Klue and downstream customers. The group has been linked by multiple defenders to activity aligned with the ShinyHunters data-extortion ecosystem, and a Telegram account claiming to represent ShinyHunters also took credit for the Klue-related operation. Public reporting has also associated the Klue intrusion cluster with Microsoft tracking under Storm-3138. High-confidence reporting indicates that Icarus operates primarily as an extortion actor focused on stealing data and threatening publication via a leak site rather than relying solely on disruptive encryption. Icarus is known for abusing trusted SaaS integrations and OAuth-based access paths, particularly in Salesforce-centric environments. In the Klue incident, the actor reportedly used a valid but dormant legacy credential tied to an old integration workflow to access Klue backend systems, implant code to harvest customer OAuth tokens, and then use those tokens to access downstream customer environments directly. The group’s post-compromise activity included bulk querying and exfiltration of CRM and related SaaS data from integrated platforms such as Salesforce and Gong. Victim reporting indicates the stolen information in these campaigns commonly included business contact data, support records, sales and marketing communications, subscription or account details, and business intelligence or opportunity notes. The actor’s tradecraft reflects a broader pattern of exploiting trust relationships rather than software vulnerabilities in the target SaaS platform itself. Reporting tied to the same ecosystem describes three recurring intrusion paths into Salesforce-connected environments: social-engineering users into authorizing malicious OAuth connected apps, stealing OAuth tokens or connection secrets from third-party vendors that already possess customer access, and abusing overly permissive guest access in Experience Cloud deployments. Icarus is most strongly tied to the vendor-token theft model through the Klue compromise, where access to one provider enabled downstream compromise of numerous customer tenants. Icarus conducts leak-site extortion and direct victim outreach. In the Klue campaign, the group listed Klue and multiple downstream organizations on a Tor-based leak site and threatened to publish stolen data unless ransom demands were met. Extortion communications reportedly imposed short deadlines and invited both the primary victim and affected downstream organizations to make contact to verify exposure or negotiate. The actor has also used the alias "mr bean" in extortion emails. Publicly named downstream victims associated with Icarus claims include Klue, Huntress, Recorded Future, Jamf, Tanium, OneTrust, Snyk, Sprout Social, LastPass, HackerOne, Insurity, GMS, and others; additional claims have included organizations in technology, business services, and financial services. Available reporting does not support a confirmed nation-state attribution. The strongest current assessment is that Icarus is a financially motivated cybercriminal actor operating within, or in close alignment with, the ShinyHunters-associated data-extortion ecosystem. Because some public claims rely on leak-site postings and victim notifications, individual victim counts and some peripheral assertions should be treated cautiously unless independently confirmed. Nonetheless, the actor is credibly associated with large-scale SaaS supply-chain abuse, downstream CRM data theft, and multi-victim extortion operations centered on compromised OAuth trust relationships.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Name used in industry reporting for the Klue-related extortion activity; overlaps with or is opportunistically associated with ShinyHunters branding in these campaigns.
Mentioned only in a related article link, not part of the main incident.
Mentioned only as a separate blog post title in related content.
Ransomware/extortion group claiming responsibility for the Klue breach, theft of customer data, and extortion activity tied to compromised Salesforce-integrated environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.