01
Icarus is tracked as a ransomware and extortion operation.1
Treat the named ransomware as the visible impact component of a broader intrusion, not as proof of who performed every earlier action.
CARDS
Icarus is retained as an emerging extortion/data-theft actor label for the Klue-linked Salesforce OAuth abuse activity. IntelliOS treats Icarus as useful operational vocabulary, while preserving source boundaries around UNC6395, Salesloft Drift, SLH, and other Salesforce-focused labels until public sources explicitly merge them.
Directory Briefing
01
Treat the named ransomware as the visible impact component of a broader intrusion, not as proof of who performed every earlier action.
02
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
03
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
04
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
05
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
06
Prioritize unusual process ancestry, remote execution, account use, network paths, and administrative changes because tooling can change faster than the actor's operational requirements.
07
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
08
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
09
Retained targeting includes Retail, Information Services, Finance, Professional&Technical Services, and Educational Services across Canada, Switzerland, Germany, and France; translate those sectors into the organization's exposed systems and high-value data.
10
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Bottom Line Up Front
Treat the named ransomware as the visible impact component of a broader intrusion, not as proof of who performed every earlier action.
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
Prioritize unusual process ancestry, remote execution, account use, network paths, and administrative changes because tooling can change faster than the actor's operational requirements.
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
Retained targeting includes Retail, Information Services, Finance, Professional&Technical Services, and Educational Services across Canada, Switzerland, Germany, and France; translate those sectors into the organization's exposed systems and high-value data.
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Decision Context
Icarus is retained as an emerging extortion/data-theft actor label for the Klue-linked Salesforce OAuth abuse activity. IntelliOS treats Icarus as useful operational vocabulary, while preserving source boundaries around UNC6395, Salesloft Drift, SLH, and other Salesforce-focused labels until public sources explicitly merge them.1,2
Actor Card Detail
Entity Type1
Emerging data-theft and extortion actor label tied to Klue/Salesforce OAuth-token abuse
First Seen1
Late April to early May 2026 public DLS footprint in ZeroFox reporting
Last Seen1
Jul 2026
Origin1
Unknown
Motivation1
Financial
Primary Access Pattern1
Abuse of trusted third-party integration credentials and OAuth tokens rather than a direct Salesforce platform exploit.
Objective1
Bulk CRM data theft, direct extortion, leak-site pressure, and monetization of business-contact, sales, support, and relationship context.
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Aliases1
Source Boundary
Icarus is source-backed for the Klue-linked extortion/data-theft activity. UNC6395 is source-backed for the earlier Salesloft Drift Salesforce OAuth campaign; IntelliOS treats that as adjacent comparator context, not a proven Icarus alias.
Targeting
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| Klue Salesforce OAuth Supply-Chain Attack3,5,8 | Klue Salesforce OAuth Supply-Chain Attack is retained in the campaign database for Icarus. A compromised legacy credential in Klue integration infrastructure enabled OAuth-token access to connected Salesforce environments. The campaign is retained as a third-party SaaS supply-chain and CRM data-exposure scenario, with Icarus included as a source-bound analytical lead that requires deconfliction from other public actor reporting. |
Indicators
SOCRadar reports 156 IOCs for this profile. IntelliOS currently retains 32 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 12 source groups tracked; 11 currently contribute retained observable or context rows.
Retained Observables
Showing 34 of 34
| Type | Value | Source |
|---|---|---|
| File Path | /services/data/v59.0/query7 | Datadog |
| File Path | /services/data/v59.0/query/{locator}7 | Datadog |
| File Path | /services/data/v59.0/query/*7 | Datadog |
| File Path | /services/data/v59.0/sobjects7 | Datadog |
| User Agent | 52387 | Datadog |
| User Agent | python-urllib/3.128 | Obsidian |
| User Agent | Python-urllib/3.127 | Datadog |
| User Agent | python-urllib/3.148 | Obsidian |
| User Agent | Python-urllib/3.147 | Datadog |
| Tool / Process | GitHub personal access token (PAT)4 | CrowdStrike |
| Tool / Process | Google Kubernetes Engine integration-service pod4 | CrowdStrike |
| Tool / Process | Klue Battlecards connected app6 | ReliaQuest |
| Tool / Process | QueryMore pagination6 | ReliaQuest |
| Tool / Process | Salesforce OAuth access token6 | ReliaQuest |
| Tool / Process | Salesforce OAuth refresh token6 | ReliaQuest |
| Tool / Process | Salesforce REST API6 | ReliaQuest |
| Tool / Process | Session Messenger extortion contact6 | ReliaQuest |
| Technique | T1199 Trusted Relationship | Retained source |
| Technique | T1528 Steal Application Access Token | Retained source |
| Technique | T1567 Exfiltration Over Web Service | Retained source |
| Network Indicator | 138.226.246.949 | FINRA |
| Network Indicator | 159.183.181.2399 | FINRA |
| Network Indicator | 159.183.215.619 | FINRA |
| Network Indicator | 212.86.125.249 | FINRA |
| Network Indicator | 213.111.148.909 | FINRA |
| Network Indicator | 94.154.32.1609 | FINRA |
| Campaign Context | Datadog reported Python-urllib/3.12, Python-urllib/3.14, and 5238 user-agent leads against Salesforce v59.0 query endpoints.7 | Datadog |
| Campaign Context | FINRA retained suspicious IP leads, the 'mr bean' alias, extortion-monitoring guidance, and member-firm mitigations for Klue OAuth/Salesforce data exfiltration.9 | FINRA |
| Campaign Context | Klue disclosed unauthorized activity affecting integration infrastructure, legacy credential access, OAuth token theft, and connected-platform data access.3 | Klue |
| Campaign Context | Klue's CrowdStrike investigation summary attributed credential collection to unauthorized code introduced through a compromised GitHub PAT and said Klue disabled affected GKE pods/PATs and rotated OAuth credentials on June 12.4 | CrowdStrike |
| Campaign Context | Obsidian reported user-agent and source-IP deviations, Global Describe reconnaissance, SOQL query activity, and QueryMore pagination as detection leads.8 | Obsidian |
| Campaign Context | ReliaQuest reported automated Salesforce REST API enumeration and QueryMore pagination using OAuth tokens from the compromised Klue integration path.6 | ReliaQuest |
| Campaign Context | Salesforce stated the issue was limited to Klue's app connection and was not caused by a Salesforce platform vulnerability.5 | Salesforce General Message 20000257 |
| Campaign Context | ZeroFox described Icarus as a financially motivated ransomware and data-extortion actor while caveating possible Scattered Lapsus$ Hunters association signals.10 | ZeroFox Intelligence Profile |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 156 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| Klue3 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| Klue4 | N/A | 3 | Public observables or source-context rows retained and displayed. |
| Salesforce Status5 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| ReliaQuest6 | N/A | 7 | Public observables or source-context rows retained and displayed. |
| Datadog Security Labs7 | N/A | 8 | Public observables or source-context rows retained and displayed. |
| Obsidian Security8 | N/A | 3 | Public observables or source-context rows retained and displayed. |
| FINRA9 | N/A | 7 | Public observables or source-context rows retained and displayed. |
| ZeroFox Intelligence10 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK | N/A | 1 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK | N/A | 1 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK | N/A | 1 | Public observables or source-context rows retained and displayed. |
Actor Chronology
| Date | Event | Evidence Boundary |
|---|---|---|
| Apr 20262 | Earliest retained public activity window | The retained profile places the actor's public leak-site footprint in late April to early May 2026. This is source-labeled activity context, not an inferred publication date. |
| Jul 20262,3 | Most recent retained activity window | Latest activity period retained by the curated Icarus profile and related Klue campaign coverage. |
| Jul 9, 2026 | IntelliOS actor record updated | Record-maintenance date; it is not treated as an actor activity or exploitation date. |
IntelliOS Intel Products
Threat Actor Profile
Exact related IntelliOS product link retained from /vault/icarus-threat-actor-snapshot.
Flash Threat Intel Brief
Exact related IntelliOS product link retained from /vault/klue-supply-chain-attack.
Comparator Brief
Adjacent Salesforce OAuth-token abuse pattern used for UNC6395/Salesloft Drift deconfliction.
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Icarus | Baseline actor-card record and ransomware/extortion directory source. | Useful as a discovery and profile seed; IntelliOS layers direct public reporting and source deconfliction on top. |
| Public reporting / direct notices | Icarus / Icarus hackers / Icarus extortion group | Supports the Klue-linked extortion/data-theft narrative and downstream disclosure matrix. | Primary victim notices control exact impact. Leak-site or claim-only lists are not treated as confirmed victims. |
| MITRE ATT&CK | Behavior mappings | Used for T1199, T1528, T1078, T1119, and T1567 behavior classification. | MITRE technique mappings classify behavior; they do not prove actor identity. |
| Google/GTIG and FBI | UNC6395 / Salesloft Drift | Retained as adjacent Salesforce OAuth-token theft comparator context. | Not merged into Icarus unless a reliable source explicitly merges the labels. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Icarus.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/icarus | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | Klue: Recent Security Incident https://klue.com/blog/an-update-on-recent-klue-security-incident | Primary Vendor Disclosure |
| 4 | Klue: CrowdStrike Investigation Summary and Security Improvements https://klue.com/blog/crowdstrike-investigation-summary-and-security-improvements | Primary Vendor Disclosure |
| 5 | Salesforce General Message 20000257 https://status.salesforce.com/generalmessages/20000257 | Vendor Statement |
| 6 | ReliaQuest: Klue Integration Abused in Salesforce Data Theft https://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft/ | Vendor Research |
| 7 | Datadog: Detecting the Klue Supply Chain Attack in Salesforce https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/ | Detection Guidance |
| 8 | Obsidian: Technical Analysis of the Klue Attack https://www.obsidiansecurity.com/blog/icarus-klue-salesforce-integration-supply-chain-attack | Detection Guidance |
| 9 | FINRA: Klue OAuth Breach and Salesforce Data Exfiltration https://www.finra.org/rules-guidance/guidance/cybersecurity-alert-klue-oauth-breach-and-salesforce-data-exfiltration | Regulator Guidance |
| 10 | ZeroFox Intelligence Profile: ICARUS https://www.zerofox.com/intelligence/zerofox-intelligence-profile-icarus/ | Threat Profile |