logo

New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration

ID: f61358dc-5490-55e1-bfe0-081aa19ee56a

STIX ID: report--f61358dc-5490-55e1-bfe0-081aa19ee56a

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-09

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

ReliaQuest describes "Helix," a data-extortion operation that leverages vishing and device-code phishing to capture identity session tokens, rapidly enrolls MFA for persistence, then performs scripted SharePoint enumeration and bulk downloads from hosted infrastructure (notably 179.43.185.230); the report includes IOCs, links Helix to the BlackFile/ShinyHunters ecosystem, and recommends disabling device-code flows, monitoring MFA enrollments and SharePoint queries, and rapid automated incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.