Ransomware Group intelligence
Icarus
ActiveTrack Icarus with 17 published victims and 1 known leak locations in a single intelligence view.
Overview
Icarus is tracked by Breach House as a ransomware group with 17 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 52m ago | e6ujsppajgb756x7x5ykdryvlcjynltb52eiwi6pd4bfwo6hddd6neid.onion |
Top Activity Sectors (4)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Icarus, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Icarus executes malicious payloads through PowerShell scripts to stage ransomware components.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Icarus executes ransomware binaries through Windows Service installation to maintain persistence.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Icarus modifies Windows Registry Run keys to ensure ransomware execution upon system reboot.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Icarus disables antivirus tools by terminating security processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Icarus deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Icarus uses file and directory discovery via PowerShell to enumerate critical data paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Icarus moves laterally through SMB shares using stolen credentials to compromise additional servers.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: Icarus encrypts victim files using AES-256 encryption with custom ransomware binaries targeting business documents.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Icarus inhibits system recovery by disabling backup restoration services and altering system startup configurations.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Icarus performs internal defacement by replacing victim files with ransom notes containing decryption instructions.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (17)
Search, filter and paginate the victim timeline for Icarus. Showing 1–17 of 17.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | H* id29987 View details | Japan | Manufacturing / Engineering | — | |
|
H* is a Japanese company operating in the manufacturing and engineering sector, providing various products and services to its customers. As a key player in its industry, H* has established itself as a reputable entity in Japan. H* was listed as a ransomware victim associated with Icarus |
|||||
| Ransomware | H* id29987 View details | Japan | Manufacturing / Engineering | — | |
|
Salesforce data of H*. Data stolen: SF data - Compressed |
|||||
| Ransomware | H** id29988 View details | Japan | Manufacturing / Engineering | — | |
|
H** is a Japanese company operating in the manufacturing and engineering sector, providing various products and services to its customers. The company is based in Japan and focuses on delivering high-quality solutions. H** was listed as a ransomware victim associated with Icarus. |
|||||
| Ransomware | H** id29988 View details | Japan | Manufacturing / Engineering | — | |
|
Salesforce data for this corp. Data stolen: SF data - compressed |
|||||
| Ransomware | G* id29989 View details | United States | Finance / Legal / Insurance | — | |
|
G* operates in the finance, legal, and insurance sector in the US, providing various financial and legal services. As a key player in this industry, G* offers a range of products and services tailored to meet the needs of its clients. G* was listed as a ransomware victim associated with Icarus |
|||||
| Ransomware | G* id29989 View details | United States | Finance / Legal / Insurance | — | |
|
Salesforce data for this corp. Data stolen: SF data - compressed |
|||||
| Ransomware | C* id29990 View details | — | — | ||
|
C* is a company operating in an unspecified sector and location, offering unknown services. Given the lack of information, it is difficult to provide specific details about its operations. C* was listed as a ransomware victim associated with Icarus. |
|||||
| Ransomware | C* id29990 View details | — | — | ||
|
Salesforce data for this corp. Data stolen: SF data. Compressed size. |
|||||
| Ransomware | Huntress id30092 View details | United States | IT | — | |
|
Salesforce data of Huntress. Data stolen: SF data - Compressed |
|||||
| Ransomware | HDS (Hdscorp) id30093 View details | United States | IT | — | |
|
Salesforce data for this corp. Data stolen: SF data - compressed |
|||||
| Ransomware | HDS (Hdscorp) id30093 View details | UNITED STATES | IT | — | |
|
Salesforce data for this corp. Data stolen: SF data - compressed |
|||||
| Ransomware | Gms-net id30094 View details | IT | — | ||
|
Salesforce data for this corp. Data stolen: SF data - compressed |
|||||
| Ransomware | Cqcrm id30095 View details | IT | — | ||
|
Salesforce data for Cqcrm Data stolen: SF data - compressed |
|||||
| Ransomware | Cbassociations id30096 View details | NGOs / Associations | — | ||
|
Salesforce data for this corp. Data stolen: SF data. Compressed size. |
|||||
| Ransomware | Klue.com id29994 View details | Canada | IT | — | |
|
As you've probably already heard, ***.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated. This leak/post is made to address this. We advice Klue to contact us for a swift resolution, in order not to affect the companies you work with. On the other note, if Klue doesnt want to accommodate this request, we advice the companies who want to protect their data to contact us via Session. In order to verify you're a representative of the company you claim to be, you will need to provide a certain value/field from a row on your SF. We wish for your cooperation, not your demise. Make the correct choice. Data stolen: data borrowed - not stolen |
|||||
| Ransomware | thecreditpros.com id29931 View details | United States | Finance / Legal / Insurance | — | |
|
TheCreditPros' Salesforce instance was breached and 263MB of data were taken from it, including: 01_input_fullcards.csv - 51,691 lines of full-info credit/debit cards: Id,First_Name__c,Last_Name__c,Middle_Name__c,Email__c,Credit_Card__c,CCV__c,Exp_Month__c,Exp_Year__c,SSN__c,DOB__c,Street_Address__c,City__c,State__c,Zip_Code__c,Mobile_Number__c,IP_Address__c,Transaction_ID__c,Status__c,CreatedDate 02_contacts_ssn.csv - 847,990 lines: Id,Name,FirstName,LastName,Email,Phone,MobilePhone,HomePhone,SSN_hidden_field__c,Birthdate,MailingStreet,MailingCity,MailingState,MailingPostalCode,Status__c,Bank_Account_Number__c,Bank_Name__c,Bank_Account_Type__c,CreatedDate 03_creditcards.csv - 722,403 lines: Id,Card_number__c,card_number_hidden__c,cvv__c,expiration_month__c,expiration_year__c,Active__c,BIN__c,Issuing_Bank__c,Prepaid__c,CreatedDate 04_leads.csv - 3,598 liens: Id,Name,FirstName,LastName,Email,Phone,MobilePhone,Street,City,State,PostalCode,Status,CreatedDate Pay or leak! Data stolen: PII, Credit cards |
|||||
| Ransomware | Cazh.id id28847 View details | Indonesia | IT | — | |
|
- User DB: 300,000 Users (Email, Hash, Phone, Address, DOB) for https://bkdp.cazh.id/. - KYC Vault: 7,800 Government IDs + 4,200 Selfies (including "Hold-to-Face" ID selfies). - 34 SQL Databases for associated schools (Students/Parents/Staff). - Corporate/Financial: Full Investor Database + partner documents - Collateral documents (Vehicle Registration Documents & Property Deeds) - Billing Proofs - Full src code of their services Data stolen: PII, SOURCE CODE, KYC |
|||||