Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo HELIXESG.COM

Group: Clop

Discovered by ransomware.live: 2025-11-13

Estimated attack date: 2025-11-13

Country: SG

Description:

[AI generated] Helix ESG is a leading provider of offshore energy solutions. With their extensive fleet of vessels, they offer a range of services such as marine construction, repair & maintenance, salvage & decommissioning, and underwater exploration. The company focuses on delivering innovative solutions while also prioritizing their commitment to safety and environmental protection.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 0


External Attack Surface: 2


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • mx1.helixesg.iphmx.com.
  • mx2.helixesg.iphmx.com.
TXT Records
  • duo_sso_verification=8WvQMqZ8MnzVNAas2zw4DgU7Kua0rUbBWXPCtMBn4vrkXTx7dOA7rOKyufeW1dwg
  • m6ql4sl1fy3fwpgxmyszl8n1lxrsm3rc
  • cisco-ci-domain-verification=1645113b2b6b62c4a79e03f82055d2f33b186f32d33dba3af27eecedf12c26ff
  • v=spf1 ip4:4.14.202.10 ip4:195.162.124.181 ip4:23.21.109.197 ip4:23.21.109.212 ip4:147.160.167.0/26 include:spf.protection.outlook.com include:_spf.salesforce.com -all
  • _jquznytzgkebsaes7tb7ig91fazeshy
  • adobe-idp-site-verification=4c817382f58d8c0b8aa72674003ff2aeb8d713dac21ff6e6a194a795321edb90
  • pmuu8abtpj92nb7go7bciuafeu
  • Foxit-domain-verification=27cfbb0a720cd8475d4b01a58af726a1
Cloud / SaaS Services Detected
Adobe Salesforce Cisco Cisco Duo

Leak Screenshot:

Leak Screenshot