Also known as: UNC7761, OilRig, Helix Kitten, APT34, HELIX KITTEN, CHRYSENE, tracked as, Greenbug, Earth Simnavaz, is a sophisticated, Chrysene, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, COBALT GYPSY, Gamaredon APT
Helix emerged in early 2026 from the collapse of the BlackFile operation, inheriting a vast infrastructure that includes NICENIC‑registered domains, residential proxy networks, and shared hosting back‑ends within a single autonomous system. The actor’s methodology relies on multi‑layered social engineering: vishing calls impersonating high‑level managers to trigger device‑code logins, combined with spear‑phishing emails that deliver malicious macros or Office attachments containing PowerShell implants such as Helminth and QuadAgent. Once inside a network, Helix aggressively enumerates SharePoint sites via automated scripts, registers Multi‑Factor Authentication on compromised accounts to lock out legitimate users, and extracts bulk data through DNS AAAA tunneling using DNSpionage-like techniques. Helix’s operations display high tactical flexibility: some invasions last minutes for quick extortion sweeps, while others endure weeks or months, enabling deep infiltration and ongoing espionage. The adversary also periodically integrates ransomware—leveraging the Helix platform's cryptocurrency laundering capabilities—to coerce victims into payment. This duality of criminal exploitation and state‑sponsored intelligence renders attribution challenging; Helix remains a complex threat that blends covert data collection with overt financial gain. Beyond direct breaches, the group is known to employ supply‑chain compromise vectors and public‑facing services attacks to widen access points. Its targeting has expanded into telecommunications as a means of bulk data harvesting and communication rerouting, reinforcing its reputation as a versatile, hard‑to‑detect threat actor that operates across both Eastern and Western geopolitical theaters.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Helix Kitten, also referred to as APT34/OilRig and Chrysene, is an Iranian‑linked threat actor that blends cyber‑espionage with financially motivated extortion. The group targets a broad spectrum of sectors—including government, defense, telecommunications, energy, and finance—using sophisticated spear‑phishing, watering‑hole, and public‑service exploits to gain initial access. Post‑breach, Helix performs rapid data exfiltration via covert DNS channels while also occasionally deploying ransomware for added leverage.
Goals & Targeting
Helix Kitten’s strategic objectives appear dual: first, to acquire sensitive state‑related or corporate intelligence from governments, defense contractors, and critical infrastructure operators; second, to monetize illicit gains by exfiltrating data for ransom or cryptocurrency laundering. The actor focuses on high‑value sectors in the Middle East—particularly Bahrain, Kuwait, and broader Iranian interests—but also attacks entities across the United States, Europe, Asia, and Africa. By exploiting familiar watering‑hole sites and public‑service vulnerabilities, Helix can remain undetected while gradually extracting actionable intelligence, then monetizing the breach when profitable. The actor’s operational tempo shifts between rapid extortion drives that span minutes to deliberate, prolonged infiltrations lasting months, enabling deep espionage operations. Targeted victims are often non‑profit organizations, think tanks, educational institutions, and maritime firms—entities with valuable intelligence but potentially weaker security postures. Helix’s dual posture of cybercriminal activities (ransomware, cryptocurrency laundering) and state‑driven espionage complicates defensive planning, demanding integrated security controls that address both conventional malware protection and advanced threat intelligence monitoring.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Helix has conducted multiple titled campaigns—Venture Logistics, Uber, Highwoods Properties, Morguard, and Westland Insurance—highlighting a pattern of targeting diverse customer bases while simultaneously extracting data for espionage or financial exploitation. The actor demonstrates operational adaptability, utilizing both classic spear‑phishing vectors and supply‑chain compromises to infiltrate corporate environments. Operational tempo is variable: rapid extortion sweeps may occur in as little as a few minutes, whereas deep‑state espionage missions can extend over months with sustained persistence. Victim selection spans governmental agencies, critical infrastructure providers, financial institutions, healthcare facilities, and maritime firms, often focusing on entities within the Middle East and the broader U.S./European markets. Notable tactics include leveraging social engineering via vishing for MFA bypass, harvesting of credentials post‑exfiltration, and embedding ransomware demands after establishing footholds. The actor’s use of distributed residential proxies and geo‑matched infrastructure blurs attribution and enhances command‑and‑control resilience. Overall, Helix operates with a blend of opportunistic financial motives and strategic intelligence gathering, making it an especially difficult adversary to neutralise.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is built on publicly reported intelligence and documented attack patterns, providing a high-level understanding of Helix Kitten’s capabilities. Confidence in the operational details—such as specific infrastructure reuse from BlackFile and exact C2 methods—is moderate due to reliance on limited third‑party reports. Key gaps remain around the precise timelines of campaigns, attribution certainty for each activity, and detailed evidence linking recent operations directly to the group.
No observed data linked yet.
18
Techniques
46
Tools
5
Campaigns
3
IOCs
0
Observed Data
6
Tactics