Helix
Helix is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Helix (UNC7761) is a ransomware/extortion group targeting transportation, professional services, and financial sectors.
Helix (also tracked as UNC7761) is an active ransomware/extortion group targeting transportation, professional services, and financial sectors in the US and Canada. They employ double-extortion tactics, pressuring victims by listing them on a public leak site. Defenders should focus on email-based initial access vectors, data exfiltration indicators, and encryption activity across these vulnerable North American sectors.
Helix is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Helix targets the transportation, professional services, and financial sectors in the US and Canada.
Helix uses double-extortion tactics, pressuring victims by listing them on a public leak site.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.