Helix
Attribution profile
- Type
- Crime Syndicate
- Location
- -
- Known incidents
- 2 incidents
- Sources
- 0 sources
- First seen
- 2026-06-01
- Last seen
- 2026-07-01
- Updated
- 2026-08-21 17:06
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Helix is an alias used by a hacking group that Google has linked to the broader UNC6671 collective. The group has been observed using social engineering techniques, specifically voice phishing, to obtain credentials from target organizations. In a publicly reported incident on June 1, 2026, Helix claimed to have exfiltrated mailboxes, cloud storage drives, accounts payable files, and dispatch documents from Uber Freight’s systems. Some of the exfiltrated email correspondence appeared online following the claim. Uber Freight stated that its operations were unaffected and that its systems remained normal while it reviewed the allegations. The group has reportedly amassed at least $10.6 million in ransom payments from its activities.
The observed targeting in the Uber Freight case involved a logistics and freight platform. No additional sectors or geographic regions are specified in the available reporting. The group’s tactical approach includes credential harvesting via voice phishing, and no specific malware families are mentioned in the reporting. Public sources do not mention the use of custom malware, exploit kits, or particular tooling beyond the social engineering vector. Affiliation with the UNC6671 collective is noted in the source, but the nature of that relationship is not detailed. The Uber Freight incident serves as the primary publicly documented example of Helix’s operational activity.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 0 sources.