Ransomware Group intelligence
Helix
ActiveTrack Helix with 14 published victims and 3 known leak locations in a single intelligence view.
Overview
Helix is tracked by Breach House as a ransomware group with 14 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 4h ago | helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion |
| Leak location 3 | Web location | Down checked 4h ago | helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/leaks |
| Leak location 1 | Onion service | Down checked 4h ago | helix2kvkqjzrkh3ospyukij7uemxwvbdmqberjmrudjmqy4hspwzzqd.onion |
Top Activity Sectors (4)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Helix, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Helix executes malicious payloads through PowerShell scripts dropped onto victim endpoints in Construction and Real Estate networks.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Helix executes ransomware binaries through Windows Service mechanisms to ensure persistence across reboots.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Helix disables antivirus tools by terminating security processes and modifying Windows Defender policies to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Helix clears Windows Event Logs using PowerShell commands to erase forensic evidence from Finance and Legal victims.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1070.004 File Deletion Stealth
What they do: Helix deletes Volume Shadow Copies via vssadmin and backup artifacts to prevent recovery from affected US systems.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Helix uses file and directory discovery via PowerShell to enumerate critical business data in Transportation and Finance directories.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Helix moves laterally through SMB/Windows Admin Shares targeting Logistics servers using stolen credentials from initial access.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: Helix archives stolen financial records and travel data using utility commands before exfiltration to C2 servers.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: Helix encrypts victim files using custom ransomware binaries targeting Transportation and Finance data stores for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Helix stops critical services like SQL Server and backup utilities via net stop commands to disrupt Logistics operations.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
Victims (14)
Search, filter and paginate the victim timeline for Helix. Showing 1–14 of 14.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | AmSpec id32010 View details | United States | Manufacturing / Engineering | ||
|
AmSpec is a company operating within the United States manufacturing and engineering sectors, providing specialized technical and operational offerings relevant to industrial production, design, and engineering workflows. As cataloged in this threat-intelligence index, AmSpec is classified as a ransomware victim entity. The association links this organization to the Helix threat actor or source within the ransomware incident context. This listing reflects the entity's sector profile, geographic origin, and documented relationship to Helix without disclosing unverified breach details. The entry serves as a structured reference for cybersecurity professionals monitoring ransomware activity across industrial and engineering environments. |
|||||
| Ransomware | AmSpec id32010 View details | United States | Manufacturing / Engineering | ||
|
AmSpec is live. T1 unlocks on the current 24-hour cadence, then 24 hours per remaining tier. |
|||||
| Ransomware | Delek US id31874 View details | United States | — | ||
|
Delek US is live. T1 unlocks in 12 hours, then 24 hours per remaining tier. |
|||||
| Ransomware | Kennedy Jenks id31774 View details | United States | — | ||
|
Kennedy Jenks is live. T1 is unlocked. T2 in 24 hours, then one day each through T4. |
|||||
| Ransomware | Venture Logistics id31404 View details | United States | Transportation / Travel / Logistics | ||
|
Venture Logistics is a US-based company operating in the transportation, travel, and logistics sector, providing various services to facilitate the movement of goods. The company's offerings cater to the needs of its clients across the United States. Venture Logistics was listed as a ransomware victim associated with Helix. |
|||||
| Ransomware | Venture Logistics id31404 View details | United States | Transportation / Travel / Logistics | ||
|
SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. |
|||||
| Ransomware | Uber id31405 View details | United States | Transportation / Travel / Logistics | ||
|
Uber Freight is a logistics and transportation company based in the United States, offering a range of services to facilitate the movement of goods. The company operates in the transportation and travel sector, providing solutions for shippers and carriers. Uber Freight is listed as a ransomware victim associated with Helix |
|||||
| Ransomware | Uber id31405 View details | United States | Transportation / Travel / Logistics | ||
|
SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. |
|||||
| Ransomware | Highwoods Properties id31406 View details | United States | Construction / Real Estate | ||
|
Highwoods.com is a US-based company operating in the construction and real estate sector, offering various services related to property development and management. The company is involved in the acquisition, development, and management of office and industrial properties. Highwoods.com was listed as a ransomware victim associated with Helix |
|||||
| Ransomware | Highwoods Properties id31406 View details | United States | Construction / Real Estate | ||
|
SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. |
|||||
| Ransomware | Morguard id31407 View details | United States | Construction / Real Estate | ||
|
Morguard is a US-based company operating in the construction and real estate sector, offering various services and solutions. The company is involved in the development, management, and ownership of real estate properties. Morguard was listed as a ransomware victim associated with Helix. |
|||||
| Ransomware | Morguard id31407 View details | United States | Construction / Real Estate | ||
|
Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication. |
|||||
| Ransomware | Westland Insurance id31408 View details | Canada | Finance / Legal / Insurance | ||
|
Westlandinsurance.ca is a Canadian company operating in the finance and insurance sector, providing various insurance services to clients across Canada. As part of the finance and insurance sector, the company plays a crucial role in offering financial protection and risk management solutions. Westlandinsurance.ca was listed as a ransomware victim associated with Helix |
|||||
| Ransomware | Westland Insurance id31408 View details | Canada | Finance / Legal / Insurance | ||
|
Westland reached out, got the full demand, then stalled with no serious number. Contacting us and dragging process is not negotiation. |
|||||