Icarus is a financially motivated cybercriminal group conducting data-theft extortion against organizations including technology, cybersecurity, business services, and financial services companies. It operates a data leak site and pressures victims through threats to publish stolen information, direct outreach to affected customers, and response deadlines. Its documented operations include victims in the United States and Canada. The group's June 2026 Klue-related activity is also tracked as Storm-3138. Icarus compromised Klue, a Canadian competitive-intelligence SaaS provider, by abusing a long-unused but still-active legacy integration credential. The intrusion involved a compromised GitHub personal access token and an unauthorized code update to Klue's integration service that harvested customer integration credentials, including Salesforce OAuth access and refresh tokens. The attackers abused these tokens and existing integration permissions to access downstream customer Salesforce environments and export CRM records through API queries. Stolen information included business contacts, account records, pricing, contract details, sales communications, and renewal information. Affected organizations included Huntress, Recorded Future, Jamf, Tanium, LastPass, and other software providers. Icarus subsequently attempted to extort both Klue and its customers. This operation used data theft and disclosure threats rather than demonstrated file encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised Klue in a data-extortion incident in which payment reportedly did not prevent continued exposure of victim information.
Ransomware/extortion group claiming responsibility for the Klue supply-chain-style compromise, using stolen OAuth tokens from Klue integrations to access customer Salesforce environments and extort both Klue and affected clients.
Relatively new ransomware/extortion group described as conducting a SaaS supply chain compromise of Klue, exfiltrating sensitive CRM data and contributing to ongoing extortion risk even after ransom payment.
Conducted a supply chain attack against Klue by compromising a legacy integration credential, deploying malicious code to harvest OAuth tokens, and using those tokens to access multiple customer Salesforce environments for large-scale data export.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.