Uncovering Helix: A New Data Extortion Group with Links to BlackFile and ShinyHunters (2026)

In the ever-evolving landscape of cyber threats, the emergence of the Helix data extortion group has caught the attention of security researchers. This group, identified by ReliaQuest, operates in a sophisticated manner, employing a range of tactics that showcase a high level of organization and adaptability.

Unveiling the Helix Threat

The Helix group's modus operandi involves a combination of voice phishing, device code phishing, and automated SharePoint data theft. What makes this particularly fascinating is the group's ability to adapt its approach across multiple incidents, relying on shared infrastructure and a well-coordinated strategy. This level of sophistication suggests a highly skilled and resourceful adversary.

One of the key insights from ReliaQuest's analysis is the group's focus on identity systems rather than traditional malware-based attacks. By persuading staff to enter device codes, attackers gain access to valid session tokens, effectively bypassing the need for direct password requests. This approach, in my opinion, highlights a clever manipulation of human behavior, leveraging social engineering techniques to achieve their goals.

A Deeper Dive into the Tactics

The group's tactics extend beyond initial access. Once inside, they swiftly register a new MFA Authenticator app, ensuring persistence and leaving minimal traces. This clever use of legitimate user actions demonstrates a deep understanding of the target environment and a strategic approach to maintaining access.

The post-access behavior is consistent across incidents, with a clear progression from manual discovery to automated collection. The use of scripted tools to enumerate and download SharePoint material in bulk showcases the group's technical prowess and efficiency. Some incidents progressed rapidly, moving from access to mass exfiltration within an hour, while others unfolded over days, demonstrating a patient and calculated approach.

Infrastructure and Connections

A central aspect of the analysis is the reuse of infrastructure. The domain oskeysync[.]com, registered through NICENIC, has been linked to earlier campaigns tied to BlackFile, ShinyHunters, and the Scattered Spider network. This shared infrastructure suggests a fragmented ecosystem where personnel, methods, and resources overlap.

The proximity of IP addresses used for exfiltration further strengthens the connection between Helix and the BlackFile ecosystem. While not definitive proof, it adds to the growing body of evidence suggesting a close alignment or shared resources between these groups.

Shifting Focus: Identity-Based Intrusion

The attacks by the Helix group highlight a broader trend in extortion cases: a shift towards identity-based intrusion. Instead of relying on malware or obvious backdoors, these attackers leverage valid sessions, legitimate MFA registration, and normal cloud services to remain stealthy.

The use of residential proxies, geo-matched to the target's city, reduces the risk of triggering travel-related alerts. This clever tactic, combined with the rotation of residential IP addresses, blends their activity into the ordinary login noise, making detection more challenging.

Defensive Strategies and Recommendations

ReliaQuest's recommendations focus on disabling device code authentication, a confirmed entry method for the Helix group. Additionally, limiting access to sensitive SaaS applications to managed endpoints and blocking newly registered domains at the proxy or DNS layer are crucial steps to mitigate the risk.

The group's ability to test containment measures within a short timeframe highlights the need for swift and proactive response strategies. Standard response steps, such as password resets and account disabling, remain effective when implemented promptly.

Final Thoughts

The Helix data extortion group represents a complex and evolving threat in the cyber landscape. Their sophisticated tactics, combined with a focus on identity-based intrusion, require a proactive and adaptive defense strategy. As the data extortion market continues to fragment, organizations must stay vigilant and prioritize recurring methods over specific group branding. The insights gained from ReliaQuest's analysis provide a valuable framework for defenders to enhance their security posture and stay ahead of these evolving threats.

Uncovering Helix: A New Data Extortion Group with Links to BlackFile and ShinyHunters (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Greg O'Connell

Last Updated:

Views: 6843

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.