Uncovering Helix: A New Data Extortion Group with Links to BlackFile and ShinyHunters (2026)

In the ever-evolving landscape of cyber threats, the emergence of new data extortion groups like Helix is a constant reminder of the need for vigilance and adaptability. As an expert in the field, I find the tactics employed by such groups particularly intriguing, especially when they mirror those of more established players like BlackFile and ShinyHunters. This article delves into the intricacies of the Helix group, its methods, and the implications for organizations worldwide.

The Helix Group: A New Player in Data Extortion

The discovery of the Helix group by ReliaQuest sheds light on a previously unreported data extortion campaign. What sets Helix apart is its use of voice phishing, device code phishing, and automated SharePoint data theft, all of which are part of a broader pattern seen across multiple incidents. This suggests an organized operation rather than isolated intrusions, which is a worrying trend in the fast-changing data extortion landscape.

Infrastructure and Branding: A Fragmented Ecosystem

One of the most striking aspects of the Helix campaign is its reuse of infrastructure. The domain oskeysync[.]com, registered through NICENIC, has been linked to earlier campaigns tied to BlackFile, ShinyHunters, and the Scattered Spider or The Com network. This proximity in infrastructure, tradecraft, and timing raises questions about the relationships between these groups. It's possible that Helix is another offshoot or a closely aligned actor using the same playbook, which is a common trend in the data extortion market.

Identity-Based Intrusion: A Shifting Trend

The attacks carried out by Helix highlight a broader shift in extortion cases toward identity-based intrusion. Instead of deploying malware or creating obvious backdoors, the operators used valid sessions, legitimate MFA registration, and normal cloud services to stay under the radar. This approach, which relies on residential proxies geo-matched to the target's city and automated SharePoint collection, serves as a clear technical fingerprint. It suggests a deliberate separation between the sign-in stage and the collection stage, which is a worrying trend for organizations.

Defensive Steps: What Organizations Can Do

The single most effective defensive measure against the Helix group is to disable device code authentication, which was confirmed as the entry method in the Helix intrusions. Organizations should also restrict the feature to a narrow group of managed devices and watch for unusual device code requests. Limiting access to sensitive SaaS applications such as SharePoint and Exchange to managed endpoints only can also block the use of unmanaged devices seen in the incidents reviewed. Blocking newly registered domains at the proxy or DNS layer can also help catch the short-lived infrastructure often used in data extortion campaigns.

Conclusion: The Need for Vigilance and Adaptability

The emergence of the Helix group serves as a stark reminder of the need for vigilance and adaptability in the face of evolving cyber threats. As an expert in the field, I believe that organizations must pay less attention to the branding of specific groups and more to recurring methods. The speed of fragmentation in the data extortion market means that new names are appearing faster than many organizations can map them. By staying informed and implementing defensive steps, organizations can better protect themselves against the Helix group and other emerging threats.

Uncovering Helix: A New Data Extortion Group with Links to BlackFile and ShinyHunters (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Foster Heidenreich CPA

Last Updated:

Views: 5427

Rating: 4.6 / 5 (56 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Foster Heidenreich CPA

Birthday: 1995-01-14

Address: 55021 Usha Garden, North Larisa, DE 19209

Phone: +6812240846623

Job: Corporate Healthcare Strategist

Hobby: Singing, Listening to music, Rafting, LARPing, Gardening, Quilting, Rappelling

Introduction: My name is Foster Heidenreich CPA, I am a delightful, quaint, glorious, quaint, faithful, enchanting, fine person who loves writing and wants to share my knowledge and understanding with you.