datadog-security-labs · Crawled Jul 18, 2026
Detecting the Klue supply chain attack in Salesforce instances
4 IoCs 1 Malware
Read original article ↗
AI Summary
In June 2026, the threat actor group 'Icarus' conducted a supply chain attack by compromising Klue's backend systems, leveraging dormant OAuth credentials to gain unauthorized access to customer Salesforce and Gong environments. The actor exfiltrated sensitive CRM data including business contacts, price quotes, and sales communications by abusing API queries with stolen OAuth tokens. Klue responded by revoking access and alerting customers, while the actor initiated an extortion campaign using Session Messenger. The attack highlights risks associated with third-party integrations and improper credential lifecycle management.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 4 extracted
MITRE ATT&CK TTPs 16 techniques
T1048 Exfiltration Over Alternative Protocol · Exfiltration T1059 Command and Scripting Interpreter · Execution T1078 Valid Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1089 T1089 T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1195.002 Compromise Software Supply Chain · Initial Access T1212 Exploitation for Credential Access · Credential Access T1213 Data from Information Repositories · Collection T1499 Endpoint Denial of Service · Impact T1530 Data from Cloud Storage · Collection T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1566.002 Spearphishing Link · Initial Access