Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators A New Name in the Data Extortion Ecosystem?

179.43.171.42

TLP:CLEAR
Active

IPv4 Address

Description

A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.

Sightings (0)

No sightings recorded yet

Details

Name / Label
A New Name in the Data Extortion Ecosystem?
Pattern Type
STIX
Confidence
75%
Valid From
Jul 23, 2026 16:00
Total Sightings
0
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 179.43.171.42

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.