Helix is a financially motivated data-extortion brand associated with the broader cybercriminal activity cluster tracked as UNC6671 and linked by multiple researchers to the BlackFile, Redact, Pink, and Falcon brands. The actor is known for identity-centric intrusions rather than exploitation of software vulnerabilities, relying heavily on social engineering to obtain access to enterprise cloud environments and then monetizing stolen data through extortion. Helix commonly uses voice phishing against employees, often impersonating IT help desk personnel and sometimes managers or other internal staff, to create urgency around security migrations, passkey enrollment, or account issues. Observed tradecraft also includes device code phishing, adversary-in-the-middle credential harvesting, multi-factor authentication abuse, registration of attacker-controlled MFA devices for persistence, password-reset abuse, deletion of security notifications from compromised mailboxes, and theft or abuse of authenticated sessions. After access is established, Helix conducts reconnaissance in Microsoft 365, SharePoint, OneDrive, and sometimes Okta-connected environments, then uses automated collection and exfiltration workflows to steal large volumes of cloud-hosted data. Helix operates as an extortion actor centered on data theft and threatened publication. Victim handling has included leak-site postings, phased release countdowns, and tiered exposure of stolen SharePoint libraries, indicating structured pressure tactics designed to force payment. Reporting also ties the broader UNC6671 ecosystem to multimillion-dollar ransom collections in 2026. Helix has targeted organizations in transportation, financial services, real estate, insurance, health care, technology, hospitality, professional services, and legal and private-equity-related environments, with a notable emphasis on high-value corporate data that can increase extortion leverage. Known victims publicly associated with the Helix brand include organizations in the United States and Canada such as Uber Freight, Venture Logistics, Kennedy Jenks, Highwoods Properties, Westland Insurance, and Morguard. Additional reporting has associated Helix-linked activity with campaigns against major U.S. financial and investment firms. While some researchers have noted overlaps with ShinyHunters tradecraft and infrastructure, those links remain unconfirmed; the strongest high-confidence association is Helix’s placement within the UNC6671/BlackFile-derived extortion ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Kennedy Jenks and operating a staged extortion timeline ('T1 is unlocked. T2 in 24 hours, then one day each through T4').
Claimed responsibility for breaching Uber Freight and stealing roughly 1 million files, publishing the data on its leak site; also described as associated with other recent incidents involving major firms.
Extortion group claiming theft of nearly 1 million files from Uber Freight and listing the company on its data leak site.
Conducting hacking and extortion attacks against organizations, including transportation companies, financial firms, and private equity firms; exfiltrating large amounts of data from cloud environments and threatening to publish it unless victims pay a ransom.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.