Activity timeline
Icarus appears in 4 tracked threats between and .
ATT&CK techniques observed
- T1195 Supply Chain Compromise — Initial Accessobserved in 4 of 4 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 4 of 4 tracked threats
- T1213 Data from Information Repositories — Collectionobserved in 4 of 4 tracked threats
- T1526 Cloud Service Discovery — Discoveryobserved in 4 of 4 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 4 of 4 tracked threats
- T1530 Data from Cloud Storage — Collectionobserved in 4 of 4 tracked threats
- T1550 Use Alternate Authentication Material — Lateral Movementobserved in 4 of 4 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 3 of 4 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 3 of 4 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 3 of 4 tracked threats
- T1552 Unsecured Credentials — Credential Accessobserved in 3 of 4 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 3 of 4 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 3 of 4 tracked threats
- T1020 Automated Exfiltration — Exfiltrationobserved in 2 of 4 tracked threats
- T1087 Account Discovery — Discoveryobserved in 2 of 4 tracked threats
Tracked threats
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data ExfiltrationCRITICAL
- Klue SaaS Integration Platform OAuth Token Compromise – Multi-Organization Salesforce CRM AccessCRITICAL
- LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)MEDIUM
- Klue OAuth Supply-Chain Breach Enables 'Icarus' Salesforce CRM Data-Theft Extortion CampaignHIGH