Malware

Icarus

Icarus is a modular stealer software, written in .NET. One module is the open source r77 rootkit.

Indicators of Compromise 5

MITRE ATT&CK TTPs 16

Source Articles

Detecting the Klue supply chain attack in Salesforce instances
In June 2026, the threat actor group 'Icarus' conducted a supply chain attack by compromising Klue's backend systems, leveraging dormant OAuth credentials to gain unauthorized access to customer Salesforce and Gong environments. The actor exfiltrated sensitive CRM data including business contacts, price quotes, and sales communications by abusing API queries with stolen OAuth tokens. Klue responded by revoking access and alerting customers, while the actor initiated an extortion campaign using Session Messenger. The attack highlights risks associated with third-party integrations and improper credential lifecycle management.
datadog-security-labs ·1mo ago
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Microsoft has identified three attack paths used by threat actors associated with ShinyHunters to compromise Salesforce environments over a year-long campaign from mid-2025 to mid-2026. The attackers exploited trusted OAuth integrations through vishing attacks, stole OAuth tokens from compromised third-party vendors like Drift, Gainsight, and Klue, and abused misconfigured guest access in Salesforce Experience Cloud sites. These methods allowed persistent access to CRM data without exploiting platform vulnerabilities, blending malicious activity with legitimate traffic. The campaigns targeted organizations across retail, education, and manufacturing sectors, leveraging social engineering, supply chain compromises, and poor identity governance.
hacker-news ·2w ago