// THREAT ACTOR
HELIX_
ActiveHELIX is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of HELIX — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2026 5
Leak site mirrors
3 mirrors tracked, 2 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onionHELIX snapshot · 2026-08-23 15:18 -
helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onionHELIX - Leaks snapshot · 2026-08-23 13:09 -
helix2kvkqjzrkh3ospyukij7uemxwvbdmqberjmrudjmqy4hspwzzqd.onion404 Not Found snapshot · 2026-08-23 16:00
Recent victims
The 50 most recent victims claimed by HELIX. Total in the index: 5.
| Date listed | Victim | Description |
|---|---|---|
| 2026-08-06 | Venture Logistics | SharePoint libraries staged T1 (least) → T4 (most). Release countdown … |
| 2026-08-06 | Uber | SharePoint libraries staged T1 (least) → T4 (most). Release countdown … |
| 2026-08-06 | Highwoods Properties | SharePoint libraries staged T1 (least) → T4 (most). Release countdown … |
| 2026-08-06 | Morguard | Morguard reached out, took extensions, then ignored the negotiation wi… |
| 2026-08-06 | Westland Insurance | Westland reached out, got the full demand, then stalled with no seriou… |