A new data-extortion group called Helix is exploiting identity-focused tactics to infiltrate SharePoint environments and steal sensitive data. The group uses voice phishing, device code phishing, and MFA abuse to gain unauthorized access.
Who is Helix?
Helix represents an emerging threat in the data-extortion landscape, focusing on identity compromise rather than traditional security vulnerabilities. The group targets organizations storing data in Microsoft SharePoint, a widely-used enterprise collaboration platform.
Attack Methods
Helix employs a sophisticated multi-layered approach:
- Vishing (Voice Phishing): Social engineering calls to trick employees into revealing credentials or sensitive information.
- Device Code Phishing: Exploiting the device authentication flow to obtain valid access tokens.
- MFA Abuse: Leveraging compromised credentials to bypass multi-factor authentication protections.
This combination allows attackers to establish legitimate access without triggering traditional security alerts.
Operational Model
As a data-extortion group, Helix likely follows the ransomware-as-a-service (RaaS) model, stealing data and threatening to publish it unless victims pay a ransom. By focusing on identity-based entry points, the group avoids detection systems designed to catch malware or network exploitation.
Why SharePoint?
SharePoint environments often contain centralized repositories of corporate documents, financial records, and proprietary information. Once inside, attackers can exfiltrate large volumes of data with minimal friction.
Defense Recommendations
Organizations should implement:
- Security awareness training focused on vishing tactics
- Conditional access policies requiring additional verification for sensitive data access
- Monitoring for unusual device code authentication requests
- Passwordless authentication where possible
- Enhanced logging and detection for SharePoint access anomalies
The emergence of Helix underscores a broader shift toward identity-focused attacks. As perimeter defenses strengthen, threat actors increasingly target the human and authentication layers where employees interact with systems.
QubesOS released a security update addressing a critical vulnerability that allows arbitrary code execution through an error reporting backchannel in the copy-to-VM function. The flaw affects multiple Qubes versions.
Android devices offer built-in protections against malicious apps, scam calls, and privacy breaches. Activating the correct security settings is essential to maximize these defenses.
File servers remain essential infrastructure for most organizations, but managing access permissions securely grows increasingly complex as systems expand. tenfold Software has outlined five best practices to simplify administration and enforce least-privilege access.
Two Nigerian men have been extradited to the U.S. and charged in connection with sextortion schemes that led to the deaths of two minors in Mississippi and North Carolina.