Icarus: Extortion Group Behind Klue OAuth Token Abuse
Icarus is an extortion group active since April 28, 2026, responsible for compromising Klue's integration infrastructure and exfiltrating customer data via OAuth…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
Icarus is an extortion group active since April 28, 2026, responsible for compromising Klue's integration infrastructure and exfiltrating customer data via OAuth…
ShinyHunters is a threat actor known for large-scale data breaches. In 2025, they used device code phishing against Salesforce tenants, compromising over…
UNC6395 is a threat actor group associated with prior OAuth abuse campaigns targeting Salesforce environments. The Klue incident shares similarities with their…
Suspected Russian-speaking threat actors compromised over 30,000 Fortinet firewalls across 194 countries in a large-scale credential harvesting campaign dubbed FortiBleed. They used…
Warlock was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
The Gentlemen was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Qilin is a ransomware operation that DevMan initially affiliated with before launching its own RaaS. The group is known for its ransomware-as-a-service…
MedusaLocker was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
DragonForce is a ransomware group whose locker DNA is shared with DevMan, as noted by Vectra AI. DevMan's ransomware is described as…
LapDogs is an attack group tracked by Mandiant that operates operational relay box networks (ORBs) using compromised end-of-life routers and IoT devices.…