A new threat group called Helix has emerged, using sophisticated tactics to steal sensitive data from SharePoint environments. The group’s modus operandi involves voice phishing, device code phishing, and multi-factor authentication abuse to gain access to victim accounts. Once inside, Helix operators quickly register a new authenticator app for persistence, browse and enumerate SharePoint, and exfiltrate files.
The initial contact with victims typically occurs through vishing, where the threat actor poses as a manager or uses caller ID spoofing to appear legitimate. In some cases, employees have reported receiving calls from individuals claiming to be their managers, requesting that they complete device code authentication to access company resources. This tactic is designed to trick targets into providing sensitive information, which is then used to gain access to their accounts.
Once in, Helix operators quickly set up a new multi-factor authenticator app, allowing them to persist in the environment even if the victim changes their password or updates their security settings. They then use automated tools to enumerate and collect data from SharePoint, often using the same IP address and user agent across multiple incidents. This behavior is a strong technical fingerprint of the Helix group.
The stolen data is typically used for extortion, with threat actors threatening to publish it unless a ransom is paid or selling it on the dark web. ReliaQuest researchers believe that Helix emerged from the ShinyHunters and BlackFile data extortion groups, based on similarities in their techniques and infrastructure. While no definitive connection has been found, the timing of Helix’s emergence – shortly after BlackFile ceased operations – raises questions about potential continuity between the two groups.
The link to ShinyHunters is particularly concerning, as Helix demonstrates a similar social engineering playbook, including vishing, employee impersonation, and targeting Microsoft 365. The use of the NICENIC registrar in Helix attacks also echoes past ShinyHunters campaigns.
To defend against Helix attacks, security teams are advised to disable device code authentication where possible, restrict SharePoint access to managed devices, and block exchanges with newly registered domains. These measures can help prevent initial access and limit the spread of malware within the environment.
As we’ve seen time and time again, even the most advanced security controls can be bypassed by determined threat actors. This is why it’s essential for organizations to regularly test their defenses through breach and attack simulation testing. By doing so, they can identify vulnerabilities before attackers do, reducing the likelihood of a successful compromise.
Source: Bleeping Computer — 2026-07-09