New Helix vishing group targets SharePoint in data theft attacks

▼ Summary
– A new data-extortion group named Helix targets SharePoint environments.
– Helix uses identity-focused tactics including voice phishing (vishing) and device code phishing.
– The group also abuses multi-factor authentication (MFA) to steal data.
A newly identified threat group, known as Helix, has emerged with a focus on data extortion, employing a sophisticated blend of identity-based attacks to compromise SharePoint environments. Their playbook includes voice phishing (vishing), device code phishing, and the abuse of multi-factor authentication (MFA) to bypass security controls and exfiltrate sensitive data.
Helix’s operations center on manipulating human trust and technical authentication processes. Attackers first initiate vishing calls to employees, impersonating IT support or trusted vendors to extract credentials. Once they gain a foothold, they exploit device code phishing to trick users into authorizing malicious logins without triggering typical MFA alerts. This allows them to maintain persistent access to SharePoint, where they can steal confidential documents and intellectual property.
The group’s reliance on MFA abuse highlights a growing trend in cybercrime: attackers are not trying to crack encryption but to exploit authentication workflows. By intercepting or bypassing second-factor requests, Helix can move laterally within cloud environments undetected. Security researchers warn that this tactic is particularly effective against organizations that lack conditional access policies or rigorous training on phishing resistance.
To defend against Helix and similar threats, experts recommend implementing strong passwordless authentication, enforcing device compliance checks, and educating employees to verify any unsolicited requests for credentials or codes. Regular audits of SharePoint permissions and session activity can also help detect unauthorized access early. As data extortion groups evolve, organizations must treat identity security as a frontline defense rather than a back-end afterthought.
(Source: BleepingComputer)




