As cited
Copy frozen at (site build).
threat intel
Helix, a New Name in the Data Extortion Ecosystem?
ReliaQuest researchers identified a previously unreported data extortion group called Helix that uses vishing, device code phishing, and automated SharePoint exfiltration to target multiple organizations. The group's tactics and infrastructure show strong similarities to the defunct BlackFile group and ShinyHunters, suggesting it either emerged from or operates within the same ecosystem. Defenders can significantly reduce risk by disabling device code authentication, restricting SaaS applications to managed endpoints, and blocking newly registered domains.
Why it matters: Organizations face active SharePoint-targeting extortion campaigns using identity-based techniques that bypass conditional access; defenders should prioritize device code authentication disablement and managed endpoint controls to close the entry points Helix exploits.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Helix, a New Name in the Data Extortion Ecosystem?
ReliaQuest researchers identified a previously unreported data extortion group called Helix that uses vishing, device code phishing, and automated SharePoint exfiltration to target multiple organizations. The group's tactics and infrastructure show strong similarities to the defunct BlackFile group and ShinyHunters, suggesting it either emerged from or operates within the same ecosystem. Defenders can significantly reduce risk by disabling device code authentication, restricting SaaS applications to managed endpoints, and blocking newly registered domains.
Why it matters: Organizations face active SharePoint-targeting extortion campaigns using identity-based techniques that bypass conditional access; defenders should prioritize device code authentication disablement and managed endpoint controls to close the entry points Helix exploits.
- Source published
- First seen by Cybersecurity Tracker