A new data-extortion group called Helix is making the rounds, and its playbook is all about identity tricks.
Researchers at ReliaQuest tracked the group’s methods. It starts with vishing — voice phishing. In some cases, attackers called employees while impersonating their manager, using caller ID spoofing to look legit. The goal? Trick targets into device-code phishing schemes that hand over account access.
Once inside a SharePoint environment, Helix operators move fast. They register a new multi-factor authenticator app for persistence, then browse and enumerate SharePoint before bulk-downloading files. The stolen data gets used for extortion — pay up or it gets published — or sold to other cybercriminals.
The exfiltration behavior is Helix’s signature. ReliaQuest notes that automated enumeration and collection was identical across incidents. The group used IP 179.43.185[.]230 with the python-requests/2.28.1 user-agent, issuing contentclass:STS_Site and wildcard searches to inventory everything reachable.
Who’s behind Helix? ReliaQuest sees connections to ShinyHunters and the now-defunct BlackFile group. The techniques overlap heavily — vishing, employee impersonation, targeting Microsoft 365, SharePoint data theft. One attack even used an exfiltration IP in the same autonomous system (AS 51852) that hosted a confirmed BlackFile IP. Helix emerged shortly after BlackFile shut down in April, which suggests a possible rebrand.
As for what to do about it: ReliaQuest’s top recommendation is disabling device code authentication where possible. Restricting SharePoint access to managed devices and blocking exchanges with newly registered domains also helps — Helix typically uses fresh domains in its attacks.
