logo

New Helix vishing group emerges in SharePoint data theft attacks

ID: c723eb4b-1fd8-5032-abfb-38782debd2e2

STIX ID: report--c723eb4b-1fd8-5032-abfb-38782debd2e2

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

ReliaQuest has identified a data-extortion group called Helix that uses social-engineering-heavy tactics (vishing, device-code phishing, MFA abuse) to access Microsoft 365/SharePoint accounts, register persistent authenticators, automate enumeration/download of SharePoint content (notably from IP 179.43.185.230 with user-agent 'python-requests/2.28.1'), and exfiltrate files to extort or sell; researchers note connections to ShinyHunters and BlackFile and recommend disabling device code authentication and restricting SharePoint to managed devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.