A new and highly effective data-extortion group has emerged, targeting organizations through a combination of identity-focused tactics and social engineering. The group, known as Helix, has already been linked to several high-profile attacks against companies such as Medtronic, Nissan, and Kodak.
Helix’s modus operandi involves initial contact with employees via voice phishing (vishing) calls, where the attackers impersonate a manager or use caller ID spoofing to appear legitimate. The goal is to trick the target into divulging sensitive information, which is then used to gain access to their accounts through device-code phishing schemes.
Once inside, Helix operators quickly register new multi-factor authenticator apps for persistence and then proceed to browse and enumerate SharePoint environments before exfiltrating files. The stolen data is typically used to extort victim organizations by threatening to publish it unless a ransom is paid or it is sold to other cybercriminals.
The researchers at ReliaQuest, the cybersecurity firm that uncovered Helix’s activities, note that the group’s strongest technical fingerprint lies in its SharePoint exfiltration behavior. Specifically, they observe that automated enumeration and collection are identical across incidents and can be identified by a specific IP address (179.43.185[.]230) using a particular user-agent (python-requests/2.28.1).
Interestingly, ReliaQuest believes that Helix may have emerged from the now-defunct BlackFile data extortion group, which targeted organizations using identity-based attacks and social engineering before ceasing operations in April. The researchers point to several clues linking Helix to ShinyHunters and BlackFile, including similarities in their social engineering playbook and use of shared resources.
The emergence of Helix raises concerns that other groups may be attempting to continue the work of defunct operations such as BlackFile. ReliaQuest notes that Pink and Redact are potential successors to this type of attack.
To mitigate the risk of a Helix-style attack, researchers recommend disabling device code authentication where possible, restricting SharePoint access to only managed devices, and blocking exchanges with newly registered domains, which Helix typically uses in its attacks.
It’s clear that organizations need to be vigilant in defending against these types of attacks. As one researcher notes, “Test every layer before attackers do” – by regularly simulating breach scenarios and testing SIEM and EDR rules, security teams can identify vulnerabilities and prevent successful attacks from going undetected.
Source: Bleeping Computer — 2026-07-09