Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

HELIXESG.COM

HELIXESG.COM

Group Clop
Discovered 2025-11-13 19:13 UTC
Est. attack date 2025-11-13
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

[AI generated] Helix ESG is a leading provider of offshore energy solutions. With their extensive fleet of vessels, they offer a range of services such as marine construction, repair & maintenance, salvage & decommissioning, and underwater exploration. The company focuses on delivering innovative solutions while also prioritizing their commitment to safety and environmental protection.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 0


External Attack Surface: 2


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • mx2.helixesg.iphmx.com. Cisco/IronPort
  • mx1.helixesg.iphmx.com. Cisco/IronPort
TXT Records
  • v=spf1 ip4:4.14.202.10 ip4:195.162.124.181 ip4:23.21.109.197 ip4:23.21.109.212 ip4:147.160.167.0/26 include:spf.protection.outlook.com include:_spf.salesforce.com -all
  • adobe-idp-site-verification=4c817382f58d8c0b8aa72674003ff2aeb8d713dac21ff6e6a194a795321edb90
  • Foxit-domain-verification=27cfbb0a720cd8475d4b01a58af726a1
  • _a3xb7yxxtk1k5m8fx5tsvhh3k51ra0n
  • duo_sso_verification=8WvQMqZ8MnzVNAas2zw4DgU7Kua0rUbBWXPCtMBn4vrkXTx7dOA7rOKyufeW1dwg
  • cisco-ci-domain-verification=1645113b2b6b62c4a79e03f82055d2f33b186f32d33dba3af27eecedf12c26ff
Cloud / SaaS Services Detected
Adobe Cisco Cisco Duo Salesforce

Leak Screenshot:

Leak Screenshot