Skip to content

Helix

Helix is a financially motivated data-extortion threat group active in 2026 that specializes in identity-centric intrusions against enterprise cloud environments, particularly Microsoft 365 and SharePoint.

Profile source: Mallory opens in a new tab

Helix

Family profile

Helix is a financially motivated data-extortion threat group active in 2026 that specializes in identity-centric intrusions against enterprise cloud environments, particularly Microsoft 365 and SharePoint. The group is associated with ransomware-style extortion and leak-site activity, but its operations are characterized more by data theft and coercive publication threats than by malware-heavy network encryption. Helix has been publicly linked to victim negotiations, countdown-based leak workflows, and tiered release of stolen data.

Helix commonly gains initial access through voice phishing and related social-engineering techniques, including impersonation of managers, executives, coworkers, or IT helpdesk personnel. Reported tradecraft includes device code phishing, adversary-in-the-middle credential harvesting, abuse of multi-factor authentication workflows, theft of valid sign-in sessions, and spoofing of caller identity. The actor has targeted employees on personal mobile phones and used residential proxy infrastructure aligned to victim geography to reduce detection. In compromised environments, Helix has established persistence by registering attacker-controlled MFA authenticator applications, then conducted reconnaissance and automated collection in SaaS platforms.

A defining operational pattern is rapid enumeration and bulk exfiltration of SharePoint content after account compromise. Helix has used automated searches and scripted collection to identify and steal high-value corporate data, sometimes moving from access to mass exfiltration in under an hour. The group has also been observed deleting security-related emails and alerts from compromised accounts as a defense-evasion measure. Extortion pressure includes threats to publish stolen information, operation of leak infrastructure, and staged or timed release mechanisms for exfiltrated data.

Victimology indicates a focus on organizations holding sensitive business information and broad cloud collaboration footprints. Reported targets and victims span financial services, insurance, healthcare, transportation, real estate, technology, legal, manufacturing, hospitality, and education-related organizations, with a notable concentration on U.S.-based enterprises and increasing attention to financial and investment firms. The actor’s targeting suggests an emphasis on data likely to maximize extortion leverage, including confidential corporate, client, and transaction-related information.

Helix has been discussed alongside Falcon, Pink, Redact, and the broader UNC6671 cluster. Multiple researchers have assessed overlaps in infrastructure, phishing templates, victimology, and extortion methods among these brands, and Helix has also been compared with BlackFile and ShinyHunters ecosystems. However, whether Helix is a direct successor, affiliate, splinter, or simply a user of shared phishing and extortion infrastructure remains unconfirmed.

Operational record

Recent claims

MITRE ATT&CK

Helix in ATT&CK

37 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.