CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Helix, a New Name in the Data Extortion Ecosystem?

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2199

As cited

Copy frozen at (site build).

threat intel

Helix, a New Name in the Data Extortion Ecosystem?

ReliaQuest researchers identified a previously unreported data extortion group called Helix that uses vishing, device code phishing, and automated SharePoint exfiltration to target multiple organizations. The group's tactics and infrastructure show strong similarities to the defunct BlackFile group and ShinyHunters, suggesting it either emerged from or operates within the same ecosystem. Defenders can significantly reduce risk by disabling device code authentication, restricting SaaS applications to managed endpoints, and blocking newly registered domains.

Why it matters: Organizations face active SharePoint-targeting extortion campaigns using identity-based techniques that bypass conditional access; defenders should prioritize device code authentication disablement and managed endpoint controls to close the entry points Helix exploits.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Helix, a New Name in the Data Extortion Ecosystem?

ReliaQuest researchers identified a previously unreported data extortion group called Helix that uses vishing, device code phishing, and automated SharePoint exfiltration to target multiple organizations. The group's tactics and infrastructure show strong similarities to the defunct BlackFile group and ShinyHunters, suggesting it either emerged from or operates within the same ecosystem. Defenders can significantly reduce risk by disabling device code authentication, restricting SaaS applications to managed endpoints, and blocking newly registered domains.

Why it matters: Organizations face active SharePoint-targeting extortion campaigns using identity-based techniques that bypass conditional access; defenders should prioritize device code authentication disablement and managed endpoint controls to close the entry points Helix exploits.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary