Malware
Icarus
Icarus is a modular stealer software, written in .NET. One module is the open source r77 rootkit.
Indicators of Compromise 5
MITRE ATT&CK TTPs 16
T1048 T1059 T1078 T1078.004 T1089 T1098 T1133 T1190 T1195.002 T1212 T1213 T1499 T1530 T1558 T1566 T1566.002
Exfiltration Over Alternative Protocol
Exfiltration
Command and Scripting Interpreter
Execution
Valid Accounts
Defense Evasion
Cloud Accounts
Defense Evasion
T1089
Account Manipulation
Persistence
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Compromise Software Supply Chain
Initial Access
Exploitation for Credential Access
Credential Access
Data from Information Repositories
Collection
Endpoint Denial of Service
Impact
Data from Cloud Storage
Collection
Steal or Forge Kerberos Tickets
Credential Access
Phishing
Initial Access
Spearphishing Link
Initial Access
Source Articles
Detecting the Klue supply chain attack in Salesforce instances
In June 2026, the threat actor group 'Icarus' conducted a supply chain attack by compromising Klue's backend systems, leveraging dormant OAuth credentials to gain unauthorized access to customer Salesforce and Gong environments. The actor exfiltrated sensitive CRM data including business contacts, price quotes, and sales communications by abusing API queries with stolen OAuth tokens. Klue responded by revoking access and alerting customers, while the actor initiated an extortion campaign using Session Messenger. The attack highlights risks associated with third-party integrations and improper credential lifecycle management.
datadog-security-labs ·1mo ago
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Microsoft has identified three attack paths used by threat actors associated with ShinyHunters to compromise Salesforce environments over a year-long campaign from mid-2025 to mid-2026. The attackers exploited trusted OAuth integrations through vishing attacks, stole OAuth tokens from compromised third-party vendors like Drift, Gainsight, and Klue, and abused misconfigured guest access in Salesforce Experience Cloud sites. These methods allowed persistent access to CRM data without exploiting platform vulnerabilities, blending malicious activity with legitimate traffic. The campaigns targeted organizations across retail, education, and manufacturing sectors, leveraging social engineering, supply chain compromises, and poor identity governance.
hacker-news ·2w ago