Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

Icarus

Also known as:Icarus extortion group

As of 2026-07-02, Icarus is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning supply chain. Also known as Icarus extortion group. ATT&CK coverage spans 33 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1195 (Supply Chain Compromise), T1199 (Trusted Relationship), T1213 (Data from Information Repositories).

Tracked threats
42 critical · 1 high · 1 medium
First seen
2026-06-18
Last seen
2026-06-28
ATT&CK techniques
33across 4 of 4 threats
Related CVEs
0None referenced
4 tracked threat(s) · Categories: SUPPLY_CHAIN

Activity timeline

Icarus appears in 4 tracked threats between and .

ATT&CK techniques observed

33 techniques observed across 4 of 4 tracked threats · Impact (5), Collection (4), Exfiltration (4), Initial Access (4), Credential Access (3), Discovery (3)
  • T1195 Supply Chain Compromise — Initial Accessobserved in 4 of 4 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 4 of 4 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 4 of 4 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 4 of 4 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 4 of 4 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 4 of 4 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 4 of 4 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 4 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 3 of 4 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 3 of 4 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 3 of 4 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 3 of 4 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 3 of 4 tracked threats
  • T1020 Automated Exfiltration — Exfiltrationobserved in 2 of 4 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 2 of 4 tracked threats

Tracked threats