Skip to main content

Operator dossier

HELIX is a ransomware operator currently active on public leak sites. Darkfield has indexed 5 public victims claimed by this operator.

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Active ransomware operator

All groups

HELIX

5 victims indexed · last activity 1 day ago

5
Victims indexed
#263 of 381 tracked operators
Active period
Countries hit

At a glance

Status
active
First seen
Last activity
1 day ago
Onion sites
1 known endpoint

MITRE ATT&CK

76 techniques · 13 tactics

Tactics

CollectionCommand And ControlCredential AccessDefense ImpairmentDiscoveryExecutionExfiltrationInitial AccessLateral MovementPersistencePrivilege EscalationResource DevelopmentStealth

Techniques

Recent victims

Loading…

Onion infrastructure

1 known
  • http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/leaks

Source

Updated 1 day ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time HELIX posts a victim.

Add HELIX to your watchlist — Pro pings you within 5 minutes of any new HELIX leak-site post, Telegram callout, or affiliate-rebrand inference.