CARDS
CARDS
Icarus is retained as an emerging extortion/data-theft actor label for the Klue-linked Salesforce OAuth abuse activity. IntelliOS treats Icarus as useful operational vocabulary, while preserving source boundaries around UNC6395, Salesloft Drift, SLH, and other Salesforce-focused labels until public sources explicitly merge them.
This actor record is shared by the Threat Actor Cards directory, the Icarus profile page, and the Icarus Flash Threat Intel Brief so identity, aliases, source boundaries, ATT&CK mapping, and IntelliOS product links stay aligned.
Actor Card Detail
Entity Type1
Emerging data-theft and extortion actor label tied to Klue/Salesforce OAuth-token abuse
First Seen1
Late April to early May 2026 public DLS footprint in ZeroFox reporting
Last Seen1
Jul 2026
Profile Updated1
Jul 9, 2026
Origin1
Unknown
Motivation1
Financial
Primary Access Pattern1
Abuse of trusted third-party integration credentials and OAuth tokens rather than a direct Salesforce platform exploit.
Objective1
Bulk CRM data theft, direct extortion, leak-site pressure, and monetization of business-contact, sales, support, and relationship context.
Identity
Aliases1
Source Boundary
Icarus is source-backed for the Klue-linked extortion/data-theft activity. UNC6395 is source-backed for the earlier Salesloft Drift Salesforce OAuth campaign; IntelliOS treats that as adjacent comparator context, not a proven Icarus alias.
Targeting
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| Klue Salesforce OAuth Supply-Chain Attack3,5,8 | Klue Salesforce OAuth Supply-Chain Attack is retained in the campaign database for Icarus. A compromised legacy credential in Klue integration infrastructure enabled OAuth-token access to connected Salesforce environments. The campaign is retained as a third-party SaaS supply-chain and CRM data-exposure scenario, with Icarus included as a source-bound analytical lead that requires deconfliction from other public actor reporting. |
Indicators
SOCRadar reports 156 IOCs for this profile. IntelliOS currently retains 32 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 12 source groups tracked; 11 currently contribute retained observable or context rows.
Retained Observables
Showing 34 of 34
| Type | Value | Source |
|---|---|---|
| File Path | /services/data/v59.0/query7 | Datadog |
| File Path | /services/data/v59.0/query/{locator}7 | Datadog |
| File Path | /services/data/v59.0/query/*7 | Datadog |
| File Path | /services/data/v59.0/sobjects7 | Datadog |
| User Agent | 52387 | Datadog |
| User Agent | python-urllib/3.128 | Obsidian |
| User Agent | Python-urllib/3.127 | Datadog |
| User Agent | python-urllib/3.148 | Obsidian |
| User Agent | Python-urllib/3.147 | Datadog |
| Tool / Process | GitHub personal access token (PAT)4 | CrowdStrike |
| Tool / Process | Google Kubernetes Engine integration-service pod4 | CrowdStrike |
| Tool / Process | Klue Battlecards connected app6 | ReliaQuest |
| Tool / Process | QueryMore pagination6 | ReliaQuest |
| Tool / Process | Salesforce OAuth access token6 | ReliaQuest |
| Tool / Process | Salesforce OAuth refresh token6 | ReliaQuest |
| Tool / Process | Salesforce REST API6 | ReliaQuest |
| Tool / Process | Session Messenger extortion contact6 | ReliaQuest |
| Technique | T1199 Trusted Relationship | Retained source |
| Technique | T1528 Steal Application Access Token | Retained source |
| Technique | T1567 Exfiltration Over Web Service | Retained source |
| Network Indicator | 138.226.246.949 | FINRA |
| Network Indicator | 159.183.181.2399 | FINRA |
| Network Indicator | 159.183.215.619 | FINRA |
| Network Indicator | 212.86.125.249 | FINRA |
| Network Indicator | 213.111.148.909 | FINRA |
| Network Indicator | 94.154.32.1609 | FINRA |
| Campaign Context | Datadog reported Python-urllib/3.12, Python-urllib/3.14, and 5238 user-agent leads against Salesforce v59.0 query endpoints.7 | Datadog |
| Campaign Context | FINRA retained suspicious IP leads, the 'mr bean' alias, extortion-monitoring guidance, and member-firm mitigations for Klue OAuth/Salesforce data exfiltration.9 | FINRA |
| Campaign Context | Klue disclosed unauthorized activity affecting integration infrastructure, legacy credential access, OAuth token theft, and connected-platform data access.3 | Klue |
| Campaign Context | Klue's CrowdStrike investigation summary attributed credential collection to unauthorized code introduced through a compromised GitHub PAT and said Klue disabled affected GKE pods/PATs and rotated OAuth credentials on June 12.4 | CrowdStrike |
| Campaign Context | Obsidian reported user-agent and source-IP deviations, Global Describe reconnaissance, SOQL query activity, and QueryMore pagination as detection leads.8 | Obsidian |
| Campaign Context | ReliaQuest reported automated Salesforce REST API enumeration and QueryMore pagination using OAuth tokens from the compromised Klue integration path.6 | ReliaQuest |
| Campaign Context | Salesforce stated the issue was limited to Klue's app connection and was not caused by a Salesforce platform vulnerability.5 | Salesforce General Message 20000257 |
| Campaign Context | ZeroFox described Icarus as a financially motivated ransomware and data-extortion actor while caveating possible Scattered Lapsus$ Hunters association signals.10 | ZeroFox Intelligence Profile |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 156 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| Klue3 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| Klue4 | N/A | 3 | Public observables or source-context rows retained and displayed. |
| Salesforce Status5 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| ReliaQuest6 | N/A | 7 | Public observables or source-context rows retained and displayed. |
| Datadog Security Labs7 | N/A | 8 | Public observables or source-context rows retained and displayed. |
| Obsidian Security8 | N/A | 3 | Public observables or source-context rows retained and displayed. |
| FINRA9 | N/A | 7 | Public observables or source-context rows retained and displayed. |
| ZeroFox Intelligence10 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK | N/A | 1 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK | N/A | 1 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK | N/A | 1 | Public observables or source-context rows retained and displayed. |
IntelliOS Intel Products
PANDA Actor Snapshot
Source-backed IntelliOS profile for Icarus, Klue/Salesforce OAuth abuse, victim disclosures, and defensive scoping.
Related Campaign Brief
Companion campaign analysis for the Klue supply-chain incident and downstream Salesforce data exposure.
Comparator Brief
Adjacent Salesforce OAuth-token abuse pattern used for UNC6395/Salesloft Drift deconfliction.
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Icarus | Baseline actor-card record and ransomware/extortion directory source. | Useful as a discovery and profile seed; IntelliOS layers direct public reporting and source deconfliction on top. |
| Public reporting / direct notices | Icarus / Icarus hackers / Icarus extortion group | Supports the Klue-linked extortion/data-theft narrative and downstream disclosure matrix. | Primary victim notices control exact impact. Leak-site or claim-only lists are not treated as confirmed victims. |
| MITRE ATT&CK | Behavior mappings | Used for T1199, T1528, T1078, T1119, and T1567 behavior classification. | MITRE technique mappings classify behavior; they do not prove actor identity. |
| Google/GTIG and FBI | UNC6395 / Salesloft Drift | Retained as adjacent Salesforce OAuth-token theft comparator context. | Not merged into Icarus unless a reliable source explicitly merges the labels. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/icarus | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | Klue: Recent Security Incident https://klue.com/blog/an-update-on-recent-klue-security-incident | Primary Vendor Disclosure |
| 4 | Klue: CrowdStrike Investigation Summary and Security Improvements https://klue.com/blog/crowdstrike-investigation-summary-and-security-improvements | Primary Vendor Disclosure |
| 5 | Salesforce General Message 20000257 https://status.salesforce.com/generalmessages/20000257 | Vendor Statement |
| 6 | ReliaQuest: Klue Integration Abused in Salesforce Data Theft https://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft/ | Vendor Research |
| 7 | Datadog: Detecting the Klue Supply Chain Attack in Salesforce https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/ | Detection Guidance |
| 8 | Obsidian: Technical Analysis of the Klue Attack https://www.obsidiansecurity.com/blog/icarus-klue-salesforce-integration-supply-chain-attack | Detection Guidance |
| 9 | FINRA: Klue OAuth Breach and Salesforce Data Exfiltration https://www.finra.org/rules-guidance/guidance/cybersecurity-alert-klue-oauth-breach-and-salesforce-data-exfiltration | Regulator Guidance |
| 10 | ZeroFox Intelligence Profile: ICARUS https://www.zerofox.com/intelligence/zerofox-intelligence-profile-icarus/ | Threat Profile |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Icarus.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |