ctipilot.ch

Icarus extortion: dormant Klue credential → harvested OAuth tokens → bulk Salesforce CRM theft

campaign · campaign:icarus-klue-salesforce-oauth

Coverage timeline
2
first 2026-06-19 → last 2026-06-21
Briefs
2
2 distinct
Sources cited
4
4 hosts
Sections touched
2
active_threats, updates
Co-occurring entities
2
see Related entities below
2026-06-192 appearances2026-06-21

Story timeline

  1. 2026-06-21CTI Daily Brief — 2026-06-21
    updatesUPDATE: victim list grows (Huntress, Recorded Future, Tanium, Jamf, Sprout Social); Huntress details python-urllib calls to Salesforce /services/data/v59.0/query/. Icarus claims attack, demands Session contact.
  2. 2026-06-19CTI Daily Brief — 2026-06-19
    active_threatsSaaS supply-chain OAuth-token theft; Huntress self-disclosed victim

Where this entity is cited

  • active_threats1
  • updates1

Source distribution

  • huntress.com1 (25%)
  • reliaquest.com1 (25%)
  • bleepingcomputer.com1 (25%)
  • klue.com1 (25%)

Related entities

Items in briefs about Icarus extortion: dormant Klue credential → harvested OAuth tokens → bulk Salesforce CRM theft (1)

Icarus extortion group turns a dormant Klue credential into bulk Salesforce CRM theft across customers

From CTI Daily Brief — 2026-06-19 · published 2026-06-19 · view item permalink →

A newly tracked extortion actor, Icarus (active since ~April 2026), compromised the backend of Klue Battlecards — a competitive-intelligence SaaS that integrates with customer Salesforce tenants over OAuth — and used it to steal CRM data from Klue's enterprise customers (ReliaQuest, 2026-06-17). Icarus obtained a dormant/prototype-integration credential, injected code into Klue's application layer to harvest the stored OAuth access tokens for each customer's Salesforce integration, then queried the Salesforce REST API directly (/services/data/v59.0/sobjects/ enumeration and /services/data/v59.0/query SOQL) for roughly 24 hours per victim before Salesforce flagged anomalous API usage and disabled the Klue integration platform-wide. The chain maps to T1199 Trusted Relationship → T1528 Steal Application Access Token → T1078.004 Valid Cloud Accounts → T1530 Data from Cloud Storage Object, bypassing every endpoint and network control the victim operates. Huntress self-disclosed that its own Salesforce sales data (contacts, internal communications, pricing) was exfiltrated, while confirming its own systems were not breached (Huntress, 2026-06-18). Icarus contacts victims directly under the alias "mr bean" on Session Messenger. Why it matters to us: delegated-OAuth grants to third-party SaaS are a perimeter-bypassing trust path that endpoint and network controls never see. Inventory Salesforce Connected-App OAuth grants, revoke dormant/prototype integrations, enforce short token TTLs and IP-range restrictions on grant policies, and stream Salesforce Event Monitoring (SObject-enumeration and bulk-SOQL patterns from integration users) to your SIEM.