Helix Data Extortion Group: Uncovering Links to BlackFile and ShinyHunters (2026)

In today's digital landscape, data extortion groups are becoming increasingly sophisticated and elusive. The recent discovery of the Helix group, linked to the notorious BlackFile and ShinyHunters, serves as a stark reminder of the evolving threats in the cybersecurity realm.

Unveiling the Helix Group

The ReliaQuest research team has uncovered a new player in the data extortion game, a group they've dubbed Helix. What sets Helix apart is its reliance on a unique blend of voice and device code phishing, coupled with automated SharePoint data theft. This group's modus operandi showcases a well-organized and coordinated effort, utilizing shared infrastructure and targeting specific organizations with precision.

A Crowded Landscape, A Shifting Focus

The data extortion landscape is a dynamic and ever-changing environment. As ReliaQuest highlights, group names may shift rapidly, but the underlying techniques remain consistent. In the case of Helix, its connections to BlackFile and ShinyHunters suggest a fragmented ecosystem where personnel and methods overlap. This fragmentation poses a challenge for defenders, as new names emerge faster than they can be mapped.

What makes this particularly fascinating is the shift in focus towards identity-based intrusion. Instead of the traditional malware-based attacks, these groups are now leveraging valid sessions and legitimate MFA registration to gain access and remain undetected. It's a clever strategy that exploits the very systems designed to protect organizations.

The Intrusion Process: A Step-by-Step Analysis

The Helix group's intrusion process is a carefully orchestrated dance. It begins with voice phishing, where attackers impersonate managers or colleagues to persuade employees to enter device codes, thus granting them access to valid session tokens. This initial step is followed by a rapid registration of a new MFA Authenticator app, providing persistence and leaving minimal traces.

Once inside, the intruders employ a consistent sequence, moving from manual discovery to automated collection. They browse content, map SharePoint material, and download files in bulk. The speed at which this process unfolds is remarkable, with some incidents progressing from access to mass exfiltration in a matter of hours.

Infrastructure and Hosting: A Shared Signature

A central aspect of ReliaQuest's analysis is the reuse of infrastructure. Helix's use of the domain oskeysync[.]com, with target-specific subdomains, is a telltale sign of an organized operation. This domain, registered through NICENIC, has been linked to previous campaigns tied to BlackFile and ShinyHunters.

The hosting links provide further evidence of a fragmented ecosystem. The IP address used for exfiltration is in close proximity to an IP tied to a confirmed BlackFile operation. While not definitive proof, it adds to the picture of overlapping personnel and methods.

Defensive Strategies: A Focus on Methods, Not Brands

In the face of such sophisticated attacks, ReliaQuest advocates for a shift in defensive strategies. Instead of fixating on the branding of specific groups, defenders should focus on the recurring methods employed. By understanding the techniques used by these groups, organizations can better prepare and respond to potential threats.

Some key defensive steps recommended by ReliaQuest include disabling device code authentication, limiting access to sensitive SaaS applications, and blocking newly registered domains at the proxy or DNS layer. Additionally, standard response steps like password resets and session revocations remain effective when implemented swiftly.

Conclusion: A Call for Vigilance

The emergence of the Helix group serves as a wake-up call for organizations to remain vigilant and adapt their defensive strategies. As the data extortion landscape continues to evolve, staying ahead of the curve is crucial. By understanding the tactics employed by these groups and focusing on recurring methods, organizations can better protect themselves against potential intrusions.

In my opinion, the key takeaway is the need for a proactive and adaptive approach to cybersecurity. As we've seen with the Helix group, these attackers are constantly evolving their techniques. It's a cat-and-mouse game, and organizations must be prepared to think like the attackers to stay one step ahead.

Helix Data Extortion Group: Uncovering Links to BlackFile and ShinyHunters (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Msgr. Refugio Daniel

Last Updated:

Views: 6374

Rating: 4.3 / 5 (54 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Msgr. Refugio Daniel

Birthday: 1999-09-15

Address: 8416 Beatty Center, Derekfort, VA 72092-0500

Phone: +6838967160603

Job: Mining Executive

Hobby: Woodworking, Knitting, Fishing, Coffee roasting, Kayaking, Horseback riding, Kite flying

Introduction: My name is Msgr. Refugio Daniel, I am a fine, precious, encouraging, calm, glamorous, vivacious, friendly person who loves writing and wants to share my knowledge and understanding with you.