Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: UNC7761, OilRig, Helix Kitten, APT34, HELIX KITTEN, CHRYSENE, tracked as, Greenbug, Earth Simnavaz, is a sophisticated, Chrysene, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, COBALT GYPSY, Gamaredon APT

Description

Helix emerged in early 2026 from the collapse of the BlackFile operation, inheriting a vast infrastructure that includes NICENIC‑registered domains, residential proxy networks, and shared hosting back‑ends within a single autonomous system. The actor’s methodology relies on multi‑layered social engineering: vishing calls impersonating high‑level managers to trigger device‑code logins, combined with spear‑phishing emails that deliver malicious macros or Office attachments containing PowerShell implants such as Helminth and QuadAgent. Once inside a network, Helix aggressively enumerates SharePoint sites via automated scripts, registers Multi‑Factor Authentication on compromised accounts to lock out legitimate users, and extracts bulk data through DNS AAAA tunneling using DNSpionage-like techniques. Helix’s operations display high tactical flexibility: some invasions last minutes for quick extortion sweeps, while others endure weeks or months, enabling deep infiltration and ongoing espionage. The adversary also periodically integrates ransomware—leveraging the Helix platform's cryptocurrency laundering capabilities—to coerce victims into payment. This duality of criminal exploitation and state‑sponsored intelligence renders attribution challenging; Helix remains a complex threat that blends covert data collection with overt financial gain. Beyond direct breaches, the group is known to employ supply‑chain compromise vectors and public‑facing services attacks to widen access points. Its targeting has expanded into telecommunications as a means of bulk data harvesting and communication rerouting, reinforcing its reputation as a versatile, hard‑to‑detect threat actor that operates across both Eastern and Western geopolitical theaters.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Defense
Financial services
Healthcare
Aerospace
Energy
Manufacturing
Media
Non profit
Education
Maritime
Think tank

Targeted Countries / Regions

IR
TW
CN
AE
US
UA
SA
ES
PK
JP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 21 hours ago

Executive Summary

Helix Kitten, also referred to as APT34/OilRig and Chrysene, is an Iranian‑linked threat actor that blends cyber‑espionage with financially motivated extortion. The group targets a broad spectrum of sectors—including government, defense, telecommunications, energy, and finance—using sophisticated spear‑phishing, watering‑hole, and public‑service exploits to gain initial access. Post‑breach, Helix performs rapid data exfiltration via covert DNS channels while also occasionally deploying ransomware for added leverage.

Goals & Targeting

Helix Kitten’s strategic objectives appear dual: first, to acquire sensitive state‑related or corporate intelligence from governments, defense contractors, and critical infrastructure operators; second, to monetize illicit gains by exfiltrating data for ransom or cryptocurrency laundering. The actor focuses on high‑value sectors in the Middle East—particularly Bahrain, Kuwait, and broader Iranian interests—but also attacks entities across the United States, Europe, Asia, and Africa. By exploiting familiar watering‑hole sites and public‑service vulnerabilities, Helix can remain undetected while gradually extracting actionable intelligence, then monetizing the breach when profitable. The actor’s operational tempo shifts between rapid extortion drives that span minutes to deliberate, prolonged infiltrations lasting months, enabling deep espionage operations. Targeted victims are often non‑profit organizations, think tanks, educational institutions, and maritime firms—entities with valuable intelligence but potentially weaker security postures. Helix’s dual posture of cybercriminal activities (ransomware, cryptocurrency laundering) and state‑driven espionage complicates defensive planning, demanding integrated security controls that address both conventional malware protection and advanced threat intelligence monitoring.

Enhanced Description

Key Capabilities

  • spear-phishing with malicious Office documents
  • watering-hole attacks on compromised websites
  • exploitation of public-facing service vulnerabilities
  • persistence via PowerShell implants (Helminth) and custom backdoors
  • web shells like ChinaChopper
  • obfuscated scripts
  • covert DNS command-and-control communications
  • credential harvesting
  • lateral movement using living-off-the-land tools
  • supply-chain compromise activity
  • malicious PowerShell macros for initial access and persistence
  • exfiltration of data via covert DNS AAAA channels
  • execution of arbitrary commands on target machine
  • screen capture for reconnaissance
  • control of C2 infrastructure through dedicated domain names

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Credential Access
Discovery
Lateral Movement
Exfiltration
Defense Evasion

ATT&CK Techniques

T1204.002
T1204.003
T1566.001
T1189
T1190
T1059.003
T1566.002
T1059
T1059.001
T1041
T1113
T1204

Software / Tooling

Helminth
ChinaChopper
ISMAgent
QUADAGENT
ISMDoor

Campaigns & Victims

Helix has conducted multiple titled campaigns—Venture Logistics, Uber, Highwoods Properties, Morguard, and Westland Insurance—highlighting a pattern of targeting diverse customer bases while simultaneously extracting data for espionage or financial exploitation. The actor demonstrates operational adaptability, utilizing both classic spear‑phishing vectors and supply‑chain compromises to infiltrate corporate environments. Operational tempo is variable: rapid extortion sweeps may occur in as little as a few minutes, whereas deep‑state espionage missions can extend over months with sustained persistence. Victim selection spans governmental agencies, critical infrastructure providers, financial institutions, healthcare facilities, and maritime firms, often focusing on entities within the Middle East and the broader U.S./European markets. Notable tactics include leveraging social engineering via vishing for MFA bypass, harvesting of credentials post‑exfiltration, and embedding ransomware demands after establishing footholds. The actor’s use of distributed residential proxies and geo‑matched infrastructure blurs attribution and enhances command‑and‑control resilience. Overall, Helix operates with a blend of opportunistic financial motives and strategic intelligence gathering, making it an especially difficult adversary to neutralise.

IOC Patterns

  • malicious Office document attachment
  • watering-hole via compromised website
  • exploit of public-facing application vulnerabilities
  • DNS-based command-and-control traffic
  • credential harvesting activity
  • spearphishing link or malicious URL
  • email-based delivery via spear‑phishing
  • domain-based C2 with dedicated domains
  • covert DNS AAAA channel for command and control
  • malicious PowerShell embedded in Office macros
  • spear-phishing emails sent from compromised victim accounts

Recommended Actions

  • Implement anti‑phishing awareness training and enforce strict email filtering rules against spear‑phishing attachments and links.
  • Block or neutralise known malicious domains used in watering‑hole campaigns and monitor domain reputation changes.
  • Apply hardening and patch management for all public-facing services to mitigate exploitation of vulnerabilities.
  • Deploy endpoint security solutions that alert on anomalous PowerShell activity, obfuscated scripts, and execution of unknown macros.
  • Monitor DNS query traffic for abnormal patterns indicative of covert C2 channels such as DNS AAAA tunneling.
  • Enforce multi‑factor authentication across corporate accounts and restrict MFA registration to legitimate users only.
  • Apply strict privilege controls and least‑privilege principles to limit lateral movement via living‑off-the-land tools.
  • Segment critical network segments—especially telecommunications and industrial control networks—to contain data flows during breaches.
  • Maintain an up‑to‑date inventory of custom backdoors and web shells (e.g., ChinaChopper, ISMAgent) for rapid detection and removal.

Suggested Tags

Iran
APT34
Helix Kitten
OilRig
Chrysene
Cyberespionage
Spear-phishing
PowerShell implants
DNS C2
Web shell
ChinaChopper
Helminth
Telecommunications sector
Bahrain
Kuwait
Middle East
Government agencies
Defense contractors
Financial services
Energy
Manufacturing

Confidence Assessment

The analysis is built on publicly reported intelligence and documented attack patterns, providing a high-level understanding of Helix Kitten’s capabilities. Confidence in the operational details—such as specific infrastructure reuse from BlackFile and exact C2 methods—is moderate due to reliance on limited third‑party reports. Key gaps remain around the precise timelines of campaigns, attribution certainty for each activity, and detailed evidence linking recent operations directly to the group.

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. https://www.huntress.com/threat-library/threat-actors/helix-kitten — Cited by AI analysis.
  2. https://www.crowdstrike.com/en-us/blog/meet-crowdstrikes-adversary-of-the-month-for-november-helix-kitten/ — Cited by AI analysis.
  3. https://www.vectra.ai/modern-attack/threat-actors/apt34 — Cited by AI analysis.
  4. https://www.cyware.com/blog/apt34-the-helix-kitten-cybercriminal-group-loves-to-meow-middle-eastern-and-international-organizations-48ae — Cited by AI analysis.
  5. https://www.trellix.com/blogs/platform/using-mitre-advance-trellix-products/ — Cited by AI analysis.
  6. https://www.crowdstrike.com/en-us/blog/crowdstrike-achieves-99-percent-detection-coverage-in-mitre-attack-evaluations-for-security-service-providers/ — Cited by AI analysis.
  7. https://www.picussecurity.com/resource/blog/oilrig-exposed-tools-techniques-apt34 — Cited by AI analysis.
  8. https://cyber.nj.gov/threat-landscape/nation-state-threat-analysis-reports/iran-cyber-threat-operations/iran-apt34 — Cited by AI analysis.
  9. https://socprime.com/blog/detection-content-rdat-backdoor/ — Cited by AI analysis.
  10. https://www.levelblue.com/blogs/levelblue-blog/inside-apt34-oilrig-tools-techniques-and-global-cyber-threats — Cited by AI analysis.
  11. https://securityweek.com/iranian-hackers-use-quadagent-backdoor-recent-attacks/ — Cited by AI analysis.
  12. https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem/ — Cited by AI analysis.
  13. https://attack.mitre.org/groups/G0049/ — Cited by AI analysis.
  14. https://www.cisa.gov/news-events/bulletins/sb26-201 — Cited by AI analysis.
  15. https://niccs.cisa.gov/tools/nice-framework/work-role/digital-evidence-analysis — Cited by AI analysis.
  16. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  17. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet

Intel Summary

18

Techniques

46

Tools

5

Campaigns

3

IOCs

0

Observed Data

6

Tactics

Tags

APT
extortion
financial sector
healthcare sector
helix-ken
apt34
iranian threat actor
data-extortion
phishing
spearphishing-link
spearphishing-attachment
powerShell implant
backdoor
dns-recon
dnspionage
cryptocurrency laundering
credential access
lateral movement
web shell
supply chain compromise
vishing
device-code-authentication
sharepoint exfiltration
residential proxy
multi-actor ecosystem
Iran
APT34
Helix Kitten
OilRig
Chrysene
Cyberespionage
Spear-phishing
PowerShell implants
DNS C2
Web shell
ChinaChopper
Helminth
Telecommunications sector
Bahrain
Kuwait
Middle East
Government agencies
Defense contractors
Financial services
Energy
Manufacturing

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
55%
First Seen
Aug 7, 2026
Last Seen
Aug 7, 2026
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.