Known victims: 1
Objectives
Executive Summary
The Icarus threat actor is a medium-sophistication criminal group driven by organizational gain, primarily targeting organizations for ransomware and financial gain. The actor has been active since May 2026 and has been linked to at least one known victim. Organizations should be aware of the potential for targeted ransomware attacks.
Goals & Targeting
The Icarus threat actor's strategic objectives are centered around achieving organizational gain through ransomware and financial gain. The group's targeting profile is likely focused on organizations that are vulnerable to ransomware attacks, potentially including those in the healthcare, finance, and technology sectors. The typical victims of Icarus are likely to be organizations that have limited cyber security controls in place, making them easier to exploit. The group's goals are likely driven by a desire to maximize their financial returns, potentially by demanding significant ransom payments from their victims.
Enhanced Description
The Icarus threat actor's victimology is limited, with only one known victim reported to date. However, this does not necessarily mean that the group has only targeted a single organization. It is possible that Icarus has been active for some time, Flyunder the radar, and that the reported victim is simply the first to be publicly disclosed. As more information becomes available, it is likely that a clearer understanding of the group's targeting preferences and victimology will emerge. In the meantime, organizations should remain vigilant and take steps to protect themselves against the threat of ransomware and other cyber threats.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Icarus threat actor's campaign patterns are likely centered around identifying vulnerable organizations and exploiting them for financial gain. The group's operational tempo is likely to be moderate, with a focus on maximizing their returns through targeted ransomware attacks. Notable past operations include the reported attack on at least one known victim, which suggests that the group is active and looking to expand their operations. As more information becomes available, it is likely that a clearer understanding of the group's campaign patterns and operational tempo will emerge.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is low to moderate, due to the limited information available on the Icarus threat actor. There are significant information gaps, including the group's TTPs, victimology, and campaign patterns. As more information becomes available, it is likely that a clearer understanding of the group's motivations, goals, and capabilities will emerge. However, at this time, the available data should be treated with caution and considered preliminary.
No techniques linked yet.
No tools linked yet.
Icarus: H*
Ransomware attack attributed to Icarus. | Sector: Not Found | Salesforce data of H*. Data stolen: SF data - Compressed | Source: https://www.ransomware.live/id/SCpASWNhcnVz
Jun 23, 2026
TLP:CLEARIcarus: H**
Ransomware attack attributed to Icarus. | Sector: Not Found | Salesforce data for this corp. Data stolen: SF data - compressed | Source: https://www.ransomware.live/id/SCoqQEljYXJ1cw==
Jun 23, 2026
TLP:CLEARIcarus: G*
Ransomware attack attributed to Icarus. | Sector: Not Found | Salesforce data for this corp. Data stolen: SF data - compressed | Source: https://www.ransomware.live/id/RypASWNhcnVz
Jun 23, 2026
TLP:CLEARIcarus: C*
Ransomware attack attributed to Icarus. | Sector: Not Found | Salesforce data for this corp. Data stolen: SF data. Compressed size. | Source: https://www.ransomware.live/id/QypASWNhcnVz
Jun 23, 2026
TLP:CLEARIcarus: Cqcrm
Ransomware attack attributed to Icarus. | Sector: Business Services | Salesforce data for Cqcrm Data stolen: SF data - compressed | Source: https://www.ransomware.live/id/Q3Fjcm1ASWNhcnVz
Jun 22, 2026
TLP:CLEARNo observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
12
Campaigns
14
IOCs
0
Observed Data
0
Tactics