Helix
actor · actor:helix-extortion
Data-extortion cluster documented by ReliaQuest (2026-07-08), assessed as a likely continuation of the BlackFile (UNC6671) and ShinyHunters ecosystems on shared registrar and hosting-adjacent infrastructure. Uses manager-impersonation vishing to drive Entra ID device-code phishing that bypasses Conditional Access, registers a new MFA authenticator within minutes for persistence, then runs automated python-requests SharePoint enumeration and bulk exfiltration for extortion.
Coverage
2
first 2026-07-10 → last 2026-08-07
Latest activity
2026-08-07
The group behind BlackFile never stopped: GTIG ties four newer extortion brands to one operator whose lure…
Peak priority
high
2 high
Targets
finance
sectors: finance, technology, legal-services · regions: us, europe
Sources cited
4
3 hosts
2026-07-102 appearances2026-08-07
Action items (4)
Do-now tasks recorded on the entries about Helix, newest first. Check the date before acting on an older one.
- Gate new authenticator and passkey enrolment behind out-of-band identity proofing that does not run over the phone channel the request arrives on, this actor's entire initial access depends on an employee completing an enrolment during an unsolicited call, and origin-bound FIDO2 does not defend the enrolment step itself.2026-08-07The group behind BlackFile never stopped: GTIG ties…
- Block or tightly scope the Entra ID device-code authentication flow tenant-wide, ReliaQuest names this the single highest-impact control, because it neutralises the session-token capture regardless of how convincing the vishing pretext is.2026-07-10ReliaQuest: new 'Helix' extortion cluster…
- Alert on a new MFA-authenticator registration occurring within minutes of a device-code sign-in from a residential-proxy IP the account has never used, that co-occurrence is Helix's persistence artifact and is otherwise indistinguishable from normal user activity.2026-07-10ReliaQuest: new 'Helix' extortion cluster…
- Hunt SharePoint/Graph access logs for enumeration using contentclass:STS_Site and wildcard search queries at automation speed from a non-browser (python-requests) user-agent, followed by bulk downloads; the automated-collection stage is the most reliable fingerprint.2026-07-10ReliaQuest: new 'Helix' extortion cluster…
Defender insights
What each entry about Helix tells a defender to do, newest first.
Triage
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
successor of
- UNC6671ReliaQuest first assessed Helix as a likely continuation of BlackFile (UNC6240 fragmentation, 2026-07-08); GTIG corroborated with its own telemetry, placing Helix among the brands it assesses share one operator with BlackFile on shared root domains and identical phishing templates (2026-08-06), while naming splintered affiliates or shared phishing-as-a-service infrastructure as plausible alternatives
overlaps with
- ShinyHuntersshared registrar and hosting-adjacent infrastructure per ReliaQuest
Story timeline
- 2026-08-07UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey
- 2026-07-10'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
Hunting pivots
Affected products
ATT&CK techniques (15 across 10 tactics)
15 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissancePhishing for Information: Spearphishing Voice
- Initial AccessValid Accounts: Cloud Accounts · Phishing: Spearphishing Voice
- PersistenceValid Accounts: Cloud Accounts · Account Manipulation: Device Registration · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationValid Accounts: Cloud Accounts · Account Manipulation: Device Registration
- StealthIndicator Removal: Clear Mailbox Data · Valid Accounts: Cloud Accounts · Social Engineering: Impersonation
- Defense ImpairmentModify Authentication Process: Multi-Factor Authentication
- Credential AccessSteal Application Access Token · Modify Authentication Process: Multi-Factor Authentication · Adversary-in-the-Middle · Multi-Factor Authentication Request Generation
- CollectionEmail Collection: Remote Email Collection · Data from Information Repositories: Sharepoint · Data from Cloud Storage · Adversary-in-the-Middle
- Command and ControlProxy: External Proxy
- ImpactFinancial Theft
Reconnaissance TA0043
T1598.004Phishing for Information: Spearphishing Voice×1
Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1566.004Phishing: Spearphishing Voice×2
Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗
Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×2
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×2
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗
Stealth TA0005
T1070.008Indicator Removal: Clear Mailbox Data×1
Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to export and delete mailbox data via command line tools or use of APIs. Mail application data can be emails, email metadata, or logs generated by the application or operating system, such as export requests.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1684.001Social Engineering: Impersonation×1
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
Defense Impairment TA0112
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
Credential Access TA0006
T1528Steal Application Access Token×1
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1621Multi-Factor Authentication Request Generation×1
Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
Collection TA0009
T1114.002Email Collection: Remote Email Collection×1
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1213.002Data from Information Repositories: Sharepoint×2
Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗
T1530Data from Cloud Storage×1
Adversaries may access data from cloud storage.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
Command and Control TA0011
T1090.002Proxy: External Proxy×1
Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
Impact TA0040
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗
Entries about Helix (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Microsoft 365×2
- Microsoft Entra ID×2
- UNC6671×2
- Microsoft SharePoint×1
- Okta×1
- Scattered Spider×1
- ShinyHunters×1
Where this entity is cited
Source distribution
- bleepingcomputer.com2 (50%)
- cloud.google.com1 (25%)
- reliaquest.com1 (25%)
All cited sources (4)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/
- cloud.google.comGoogle Threat Intelligence Group / Mandianthttps://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/
- reliaquest.comReliaQuesthttps://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem