Icarus
Icarus is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Icarus is an active ransomware/extortion group targeting technology, professional services, and financial sectors in the US and Canada.
Icarus is an active ransomware/extortion group tracked via its public leak site, primarily targeting organizations in the United States and Canada. It focuses on the Technology, Professional Services, and Financial Services sectors. No detailed TTPs or tools are provided, but the group conducts ransomware attacks with data extortion and subsequent victim exposure. Defenders should prioritize monitoring the group's leak site, reinforcing offline backup and recovery processes, and sharing cross-sector threat intelligence.
Icarus is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Icarus primarily targets organizations located in the United States and Canada.
Defenders should prioritize monitoring Icarus's leak site, reinforcing offline backup and recovery processes, and sharing cross-sector threat intelligence.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.