IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIThreat Actor Profile

Icarus

Threat Actor Group

Threat actorExtortionSaaS intrusion
Published
24-JUN-2026
Brief Version
v2.7
Updated
24x via AI Monitoring Agents
Next AI Monitor
Daily at 6:00 AM ET for 2 years
Brief ID
PANDA-TA-ICARUS-2026-001
Template
Threat Actor Profile Template v1.0

Research Framing

1-Topic

Icarus is an emerging data-theft and extortion actor label associated in public reporting with the Klue/Salesforce OAuth incident. In this brief, the topic is not simply whether Icarus is a mature actor name; it is whether source-backed reporting shows a repeatable operational pattern: compromised SaaS integration trust, OAuth-token-backed Salesforce access, CRM data collection, and extortion pressure against downstream organizations. [1, 3, 4, 5, 6, 8, 9]

The defensible framing is that attackers abused a trusted third-party integration path rather than exploiting Salesforce itself. Klue described unauthorized activity affecting integration infrastructure and OAuth tokens, while Salesforce stated the issue was limited to Klue's app connection and did not arise from a Salesforce platform vulnerability. 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary newly adds that a compromised GitHub PAT was used to introduce unauthorized code into the integration service and collect third-party integration credentials, including Salesforce OAuth tokens. [1, 2, 3, 5, 34]

The operational concern is broader than actor naming. Public victimology now includes direct notices and reporting across organizations such as Huntress, LastPass, Jamf, Recorded Future, HackerOne, BeyondTrust, Sprout Social, Pendo, 8x8, Link11, and additional Klue customers, with impact generally framed around Salesforce, CRM, sales, support, business-contact, or customer-relationship data. [4, 7, 15, 18, 19, 20, 21, 22, 23, 24, 25, 28, 29]

For defenders, the topic should drive action around OAuth app inventory, token revocation, Salesforce API telemetry, suspicious integration-account behavior, data-exposure scoping, and extortion evidence preservation. 03-Jul-2026 · Newly retained (>24h)Klue's remediation summary adds vendor-side hardening themes around PAT elimination, GitHub Apps or short-lived credentials, automated secret scanning, audit logging, SIEM centralization, EDR, CI/CD observability, and GitHub Actions allowlisting. 30-Jun-2026 · Newly retained (>24h)FINRA's alert broadens response to Klue integrations with Salesforce, HubSpot, Gong, SharePoint, Zoom, Chorus, Clari, Google Drive, Slack, and other SaaS platforms. Attribution remains useful, but response should not wait for final confidence on whether Icarus overlaps with any other publicly named SaaS intrusion cluster. [3, 5, 26, 30, 34]

Expansion Research Add
Treat this Topic card as the operational center of the profile: Icarus is the actor label, but the control-plane issue is SaaS trust. The page should therefore be read as an actor profile plus a connected-app exposure model, not as proof of a direct Salesforce vulnerability or a uniform impact pattern across every named organization.

2-Persona / Audience Lens

3-BLUF

  • Icarus is best treated as an emerging data-theft/extortion actor or actor label tied in public reporting to the Klue/Salesforce OAuth-token supply-chain incident, not a long-established intrusion set with mature public attribution. 30-Jun-2026 · Newly retained (>24h)Newly retained (>24h) ZeroFox profiling supports an early observed window of late April to early May 2026 and financial motivation while keeping real-world operator identity unresolved. 15-Jul-2026 · Newly retained (>24h)Microsoft newly identifies the Klue incident as Storm-3138 activity inside broader ShinyHunters-associated OAuth-abuse tradecraft, which improves source deconfliction but does not by itself prove Icarus, UNC6395, Salesloft Drift, or ShinyHunters are interchangeable actor labels. [4, 5, 6, 8, 9, 31, 48]
  • The operational pattern is SaaS trust abuse: compromise or abuse Klue integration infrastructure, obtain OAuth tokens for connected platforms, and query downstream Salesforce CRM data through a trusted integration path. 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary newly clarifies the root path as a previously compromised GitHub PAT (personal access token) used to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth tokens. [1, 2, 3, 5, 34]
  • Salesforce publicly framed the issue as limited to Klue's app connection, not a Salesforce platform vulnerability; that distinction matters for legal scoping and customer communications. [2, 8]
  • Real-world exposure includes confirmed downstream organizations such as Huntress, LastPass, Jamf, and Recorded Future; 25-Jun-2026 · Addedthe monitoring run newly retained direct notices or filings for HackerOne, BeyondTrust, Sprout Social, Pendo, LastPass, and 8x8. 27-Jun-2026 · Freshly reported (<24h)Freshly reported (<24h) SecurityWeek reporting now describes roughly two dozen Klue customers with customer notifications and adds AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines to the public-notice picture. 02-Jul-2026 · Newly retained (>24h)Newly retained direct notices add Saviynt and LogicMonitor/Catchpoint as additional organization-specific boundary sources. 05-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible) Postman adds a direct Salesforce customer contact / sales-information exposure boundary, Gong non-customer-data-access caveat, and core-platform-services exclusion. 06-Jul-2026 · Newly retained (>24h)Newly retained (>24h) Deel and Insurity direct notices add business-contact/commercial CRM exposure, limited personal-data-in-CRM and active-secrets-in-CRM caveats, and platform/product/infrastructure non-impact boundaries. 08-Jul-2026 · Newly retained (>24h)Newly retained (>24h) OneTrust, Tines, and Thinkproject direct notices add CRM-related Salesforce, support-adjacent, UAT CRM, and product/platform non-impact boundaries. 19-Jul-2026 · Newly retained (>24h)OneTrust's July 10 update adds completed technical investigation, validated scope, finalized containment/remediation, no exposure beyond OneTrust's Salesforce environment after June 12 containment, and ongoing governance/compliance review. 08-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible) Cresta, AlertMedia, and ABBYY trust-center notices add direct Salesforce/CRM impact boundaries and product, infrastructure, network, technology, or customer-data non-impact statements. 09-Jul-2026 · Freshly reported (<24h)Freshly reported (<24h) Snyk adds direct forensic-closure scoping: business CRM data only, direct impacted-customer notification, and no evidence of Snyk platform or sensitive-data impact. 10-Jul-2026 · Newly retained (>24h)Newly retained (>24h) SentinelOne public partner-update coverage adds Salesforce-only containment via Klue API integration, independently verified forensic completion, no lateral movement, and no core product, cloud infrastructure, production environment, or service impact. 12-Jul-2026 · Newly retained (>24h)Newly retained (>24h) Camunda and Tanium direct notices add Camunda standard business-contact/account CRM-only scoping with support-data exclusion and Tanium Salesforce sales-account/business-contact scoping with support, password, customer-security-data, product, and cloud-infrastructure exclusions. Direct notices generally frame Salesforce/CRM, sales, support, or business-contact exposure rather than core product compromise. [4, 7, 8, 9, 15, 18, 19, 20, 21, 22, 23, 24, 25, 28, 29, 32, 33, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47]
  • Defenders should prioritize OAuth token revocation, connected-app review, Salesforce API/query telemetry, anomalous integration-account behavior, extortion communications, and data-exposure scoping. 26-Jun-2026 · Newly retained (>24h)Newly retained (>24h) practitioner analysis further emphasizes OAuth app inventory, risky-scope review, blast-radius mapping, centralized revocation, and persistence checks for new OAuth apps, admin accounts, or webhooks. 30-Jun-2026 · Newly retained (>24h)FINRA adds member-firm guidance to inspect REST API activity, OAuth token-use deviations, high-volume queries, suspicious IPs, and extortion attempts. 15-Jul-2026 · Newly retained (>24h)Microsoft adds Salesforce RTEM, connected-application attribution, high-privilege and unused app posture, app risk scoring, and CloudAppEvents hunting pivots for this class of abuse. [1, 3, 5, 26, 30, 48]

4-Executive Summary

Icarus is currently best understood as a relatively new extortion actor label tied to Salesforce data theft through compromised SaaS integration trust. Public reporting around the Klue incident says attackers gained access to Klue integration infrastructure through a compromised legacy credential, obtained OAuth tokens used to connect Klue with third-party platforms including Salesforce, and used those tokens to access data in connected customer environments. 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary newly clarifies that the access involved a previously compromised GitHub PAT used to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. [1, 3, 4, 5, 6, 8, 34]

The incident is important because it bypasses the mental model that "the customer's Salesforce was hacked" or that an employee clicked a phish. The more precise model is third-party SaaS supply-chain access: a trusted app connection had access, the token represented that trust, and attackers used it to query CRM data through legitimate Salesforce APIs until the token and integration path were disabled. Salesforce stated the issue was limited to Klue's app connection and did not arise from a Salesforce platform vulnerability. [2, 3, 5]

Real-world examples make the risk concrete. Huntress publicly disclosed that CRM data such as business contacts, price quotes, sales communications, and competitive reports were impacted, while LastPass later confirmed customer-support and business-contact data exposure through Salesforce and stated that password vaults and core services were not affected. 25-Jun-2026 · AddedThe Icarus AI Monitoring Agent newly retained direct notices from HackerOne, BeyondTrust, Sprout Social, Pendo, LastPass, and 8x8, further supporting the same boundary: Salesforce/CRM or sales-context data exposure through the Klue integration, not proof of core product compromise. [4, 7, 8, 20, 21, 22, 23, 24, 25]

27-Jun-2026 · Freshly reported (<24h)Fresh victimology reporting now puts the public notification set at roughly two dozen Klue customers and adds AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines to the public-notice picture. 27-Jun-2026 · Newly retained (>24h)The newly retained Link11 direct notice confirms certain Salesforce CRM business-contact and sales-related data exposure while excluding Link11 core systems, products, operational security infrastructure, and customer systems. [28, 29]

02-Jul-2026 · Newly retained (>24h)Newly retained (>24h) direct-notice coverage adds LogicMonitor/Catchpoint, which confirmed unauthorized access to Catchpoint's Salesforce environment and business relationship / sales activity data exposure while excluding LogicMonitor's primary Salesforce environment and production, monitoring, credential, payment, and operational customer data. 02-Jul-2026 · Newly retained; undatedSaviynt's Trust Portal notice is newly retained with no visible page-publication date and limits potential impact to certain Salesforce sales data while excluding Saviynt products, services, and customer data in Saviynt products. [32, 33]

05-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible) direct-notice coverage now adds Postman's Security & Trust Portal notice, which confirms customer contact and sales information exfiltration from Salesforce via the compromised Klue service account between June 11-12, while stating customer data was not accessed from Gong and Postman core platform services remained secure and were not impacted. [35]

06-Jul-2026 · Newly retained (>24h)Newly retained (>24h) direct-notice coverage adds Deel and Insurity. Deel confirmed a compromised Klue connection exposed business contact and commercial CRM information plus a very limited amount of personal data synced to CRM, while saying the Deel platform itself was not involved. Insurity confirmed suspicious Klue connected-app activity, cloud/product/infrastructure non-impact, CRM business-contact exposure, and a very limited set of active credentials/secrets within CRM data that were rotated or reset. [36, 37]

08-Jul-2026 · Newly retained (>24h)Newly retained (>24h) direct-notice coverage adds OneTrust, Tines, and Thinkproject. OneTrust described Klue Battlecards OAuth abuse against CRM-related Salesforce data and support-email-related records while excluding customer OneTrust platform data, tenants, passwords, and payment-card data. 19-Jul-2026 · Newly retained (>24h)OneTrust's July 10 update newly adds completed technical investigation, validated scope, finalized containment/remediation, no evidence of exposure beyond OneTrust's Salesforce environment after June 12 containment, and ongoing governance/compliance review. Tines' July 1 update completed its review and limited impact to Salesforce CRM business information, with a small number of sensitive-information cases directly notified and no Tines customer environment, workflow, credential, secret, or token impact. Thinkproject scoped the incident to a Klue-authorized UAT CRM environment and business-contact/commercial information while excluding products and the customer product platform. 08-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible) Cresta, AlertMedia, and ABBYY trust-center notices add direct Salesforce/CRM impact boundaries and product, infrastructure, network, technology, or customer-data non-impact statements. [38, 39, 40, 41, 42, 43]

09-Jul-2026 · Freshly reported (<24h)Freshly reported (<24h) direct-status coverage adds Snyk's July 8 forensic closure. Snyk said its Mandiant-assisted investigation was complete, the impact was limited to business CRM data, all impacted customers were notified directly, and no evidence of impact to the Snyk platform or sensitive data within it was found. [44]

This is closer to extortion-driven SaaS data theft than classic ransomware. Public reporting ties Icarus to leak-site pressure and extortion communications, but the source set does not show file-encrypting malware, network-wide ransomware deployment, or a direct Salesforce platform exploit. The defensible operational framing is therefore: valid SaaS trust was abused, CRM data was queried and exfiltrated, and victims then had to scope downstream exposure and extortion risk. [4, 6, 8, 9, 15]

03-Jul-2026 · Newly retained (>24h)Klue's July 1 CrowdStrike investigation summary adds containment and boundary detail without changing actor attribution: Klue says Salesforce notified it of suspected unauthorized third-party activity on June 12, Klue disabled affected GKE pods (Google Kubernetes Engine runtime workloads) and compromised GitHub PATs, rotated OAuth credentials, CrowdStrike did not identify evidence of threat-actor access outside systems related to the integration service, and there was no evidence of threat-actor activity in the Klue environment after June 12. [34]

26-Jun-2026 · Freshly reported (<24h)Freshly reported (<24h) status reporting adds a caveated live-extortion update: Klue reportedly told customers it remained in contact with Icarus, that Icarus said it was taking steps to delete data, and that the Icarus site appeared down, while a second unnamed actor claimed to have samples for a subset of customers and attempted direct extortion. This does not verify payment, operator identity, a complete data set, a confirmed 195-customer victim count, or full deletion of stolen data. [27]

30-Jun-2026 · Newly retained (>24h)Newly retained (>24h) FINRA and ZeroFox sources add actor-tradecraft and hunting precision: FINRA lists suspicious IPs and sender domains shared by companies, while ZeroFox adds suspicious API user agents, "mr bean" direct-email alias corroboration, and a first-observed late-April / early-May 2026 DLS footprint. ZeroFox's possible SLH association remains circumstantial because Icarus has not publicly acknowledged it. [30, 31]

15-Jul-2026 · Newly retained (>24h)Microsoft's July 13 research adds a source-backed comparator and nomenclature update: it describes mid-2025 to mid-2026 Salesforce abuse using OAuth consent and supply-chain paths associated with ShinyHunters tradecraft, identifies the June 2026 Klue incident as Storm-3138, and recommends Salesforce RTEM, connected-app attribution, app permission insight, high-privilege/unused-app review, risk scoring, and CloudAppEvents hunting. This improves deconfliction and detection guidance but does not merge Icarus with UNC6395/Salesloft Drift or prove a Salesforce platform vulnerability. [48]

Expansion Research Add
Treat Icarus as an attribution label with useful operational value but limited public maturity. The strongest public evidence supports an extortion actor using stolen SaaS/OAuth access paths against downstream Salesforce data. UNC6395 is source-backed for earlier Salesloft Drift OAuth-token data theft in Google and FBI reporting, and Microsoft now uses Storm-3138 for Klue while discussing ShinyHunters-associated OAuth abuse. This source set still does not prove Icarus, UNC6395, Storm-3138, and ShinyHunters are interchangeable labels. Use UNC6395 as an adjacent comparator unless a source directly merges the labels. [9, 10, 11, 48]

5-Why It Matters

6-Profile / Snapshot

7-Timeline of Known TA Group Activities

8-Public Victim / Disclosure Matrix

9-Associated Campaigns / Activity Clusters

10-How The Campaign Works

11-Term Glossary

12-Forensic Indicators & Hunting

13-TTPs / Attack Flow

14-IOCs / Observables

15-IR Playbook / Defensive Actions

16-Decision Ready Actions

17-Exploitable Technology Risks

18-Social Media / Community Signals

19-Source Summary & Confidence

20-Real World Examples

21-Source Weighting / Relevance

22-Source Deconfliction

23-About the Contributors

24-KEV and CVE Details

25-MITRE ATT&CK Lifecycle Mapping

26-Common Questions Q&A

27-Talking Points

28-Additional IntelliOS Threat Intel Products on this Topic

29-AI Agent Delta Updates

30-Citations

31-Version Change Log