SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

Icarus

💰 eCrimeMotivation: financialLast active: 2026-08-08First seen: 2026-05-05
1
linked CVEs
Targeted industries
Business ServicesFinancial ServicesNot FoundTechnology
Targeted regions
CAIDUS
On June 11, 2026, the Icarus threat group compromised Klue's backend systems, a market intelligence platform used by hundreds of enterprises to sync competitive battlecard data with CRM environments. The attackers exploited a dormant credential from an abandoned prototype integration to harvest OAuth tokens for Salesforce and Gong. Through automated API calls using Python scripts, the group exfiltrated CRM data including business contacts, price quotes, and sales communications from multiple customer Salesforce organizations. Klue detected the anomalous activity on June 12 and revoked OAuth credentials on June 13. The attackers subsequently launched an extortion campaign starting June 16, demanding victims contact them via Session Messenger within 48 hours.
Source: ransomware_live · Collected: 2026-08-10
⚡ Vulnerabilities & Exploits1 CVE
threat_actor_cve → cves / exploits.cve_ids
CVE-2025-8088
suspected

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

CVSS 8.8
KEVransomware
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs39
domaingpsfinance.co.id2026-08-08
domainabc.petitechanson.com2026-08-08
domainabc.sudsmama.com2026-08-08
domainabc.woopami.com2026-08-08
domainvnc.kcii2.com2026-08-08
sha109b0bc41f8838949d5a1c442ee2e2ec9ff892fdc2026-08-08
sha1a12db7b72879ac0f46079efd8c67e8ca0621f73b2026-08-08
sha1cc6fd90785a528883b0203138348df8bad69bb1a2026-08-08
sha1f0b182423107a04cf5f09b8559e656242a4fcc892026-08-08
sha2564741c2884d1ca3a40dadd3f3f61cb95a59b11f99a0f980dbadc663b85eb77a2a2026-08-08
domainemezonhe.me2026-08-08
domainskycloudcenter.com2026-08-08
domaindog3rj.tech2026-08-08
domainq74vn.live2026-08-08
domainabwxjp5.me2026-08-08
domainservgate.me2026-08-08
domainpr0fu5a.me2026-08-08
domainzamstats.me2026-08-08
domainpickupweb.me2026-08-08
domainzrheblirsy.me2026-08-08
domainmsonline.help2026-08-08
domaingouvn.me2026-08-08
domainabc.doublemobile.com2026-08-08
domaineditor.gleeze.com2026-08-08
domainwww.cosmosmusic.com2026-08-08
domainmcagov.cc2026-08-08
domainroldco.com2026-08-08
domainabc.3mkorealtd.com2026-08-08
domainabc.fetish-friends.com2026-08-08
domainabc.haijing88.com2026-08-08
domainabc.ilptour.com2026-08-08
domaingofile.io2026-06-25
domainhouse.com.au2026-06-18
domainrobinskitchen.com.au2026-06-18
ip138.226.246.942026-06-18
ip212.86.125.242026-06-18
ip213.111.148.902026-06-18
ip94.154.32.1602026-06-18
domainbaccarat.com.au2026-06-18
📰 Threat Intel Coverage1
Digest reports mentioning this actor (incl. aliases)
Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntressmatched as Icarus2026-06-18