Helix Data Extortion Group Exposed: Links to BlackFile & ShinyHunters Revealed (2026)

In the ever-evolving landscape of cyber threats, the emergence of new data extortion groups like Helix is a constant reminder of the need for vigilance and adaptability. This group, identified by ReliaQuest, has been orchestrating sophisticated attacks that highlight a critical shift in extortion tactics: the increasing reliance on identity-based intrusions. What makes this particularly fascinating is how Helix, despite its relatively new name, has seamlessly integrated itself into the existing ecosystem of established groups like BlackFile and ShinyHunters, sharing infrastructure, methods, and timing. This raises a deeper question: how can defenders keep pace with the rapid fragmentation and evolution of these threat actors?

One thing that immediately stands out is the group's preference for identity systems over malware. Instead of deploying malicious software or creating obvious backdoors, Helix operators gain access by persuading staff to enter device codes, allowing them to capture valid session tokens without directly asking for passwords. This approach, while subtle, has proven highly effective, as seen in the cases examined by ReliaQuest. The attackers, often spoofing caller IDs and leveraging knowledge of company reporting structures, target high-visibility employees, such as executives, whose accounts can provide broader access to company systems and stored information.

What many people don't realize is that once inside, the intruders typically register a new MFA Authenticator app on the compromised account within minutes, giving them persistence through what appears to be a legitimate user action. This leaves few obvious traces beyond the new MFA registration itself, making it challenging for defenders to detect the compromise in its early stages. The post-access behavior, characterized by manual discovery followed by automated collection, further underscores the group's sophistication and organization.

From my perspective, the reuse of infrastructure is a central aspect of the Helix campaign. The domain oskeysync[.]com, registered through NICENIC, a registrar linked to earlier campaigns tied to BlackFile, ShinyHunters, and the wider Scattered Spider or The Com network, is a key component. The proximity of the IP address used for exfiltration to one tied to a confirmed BlackFile operation further supports the idea of a fragmented ecosystem where personnel, methods, and supporting infrastructure overlap. This raises a critical point: defenders should focus less on the branding of specific groups and more on the recurring methods and infrastructure they use.

If you take a step back and think about it, the speed of fragmentation in the data extortion market means new names are appearing faster than many organizations can map them. This dynamic makes it crucial for defenders to adopt a more proactive and adaptive approach, leveraging shared threat intelligence and focusing on the underlying techniques rather than the group names. The fact that BlackFile's shutdown has led to successor brands like Pink and Redact, and that Helix may be another offshoot or a closely aligned actor, underscores the need for a more holistic and dynamic defense strategy.

A detail that I find especially interesting is the group's use of residential proxies for sign-ins, geo-matched to the target's city, reducing the chance of triggering impossible-travel alerts. This technique, combined with the rotation of residential IP addresses against a single mailbox, effectively blends the activity into ordinary login noise generated by VPNs and mobile networks. The automated SharePoint collection, using a specific user-agent and designed to map all reachable content before downloading files in bulk, further highlights the group's technical sophistication and deliberate separation between the sign-in and collection stages.

In terms of defensive steps, ReliaQuest recommends several measures. Disabling device code authentication, which was confirmed as the entry method in the Helix intrusions, is the single most effective defensive measure. Where this is not possible, organizations should restrict the feature to a narrow group of managed devices and watch for unusual device code requests. Limiting access to sensitive SaaS applications like SharePoint and Exchange to managed endpoints only would have blocked the use of unmanaged devices seen in the incidents reviewed, even after a session had been compromised. Blocking newly registered domains at the proxy or DNS layer, as the phishing infrastructure tied to Helix was recently registered, can also help catch the short-lived infrastructure often used in data extortion campaigns.

Standard response steps such as password resets, session revocation, and account disabling generally work when applied quickly enough. However, in one case, the operator tested containment within 30 to 40 minutes of an account being disabled by attempting to re-register MFA and reset the password. This underscores the importance of rapid response and the need for continuous monitoring and improvement of defensive strategies.

In conclusion, the emergence of groups like Helix, seamlessly integrated into the existing ecosystem of established threat actors, highlights the need for a more proactive and adaptive defense strategy. By focusing on recurring methods and infrastructure, leveraging shared threat intelligence, and adopting a more holistic approach, defenders can better keep pace with the rapid fragmentation and evolution of these threat actors. The key lies in understanding the underlying techniques and adopting a dynamic defense strategy that can quickly adapt to new tactics and techniques.

Helix Data Extortion Group Exposed: Links to BlackFile & ShinyHunters Revealed (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Wyatt Volkman LLD

Last Updated:

Views: 6250

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Wyatt Volkman LLD

Birthday: 1992-02-16

Address: Suite 851 78549 Lubowitz Well, Wardside, TX 98080-8615

Phone: +67618977178100

Job: Manufacturing Director

Hobby: Running, Mountaineering, Inline skating, Writing, Baton twirling, Computer programming, Stone skipping

Introduction: My name is Wyatt Volkman LLD, I am a handsome, rich, comfortable, lively, zealous, graceful, gifted person who loves writing and wants to share my knowledge and understanding with you.