New Helix vishing group emerges in SharePoint data theft attacks
ID: c723eb4b-1fd8-5032-abfb-38782debd2e2
STIX ID: report--c723eb4b-1fd8-5032-abfb-38782debd2e2
Feed Name: Bleeping Computer
ReliaQuest has identified a data-extortion group called Helix that uses social-engineering-heavy tactics (vishing, device-code phishing, MFA abuse) to access Microsoft 365/SharePoint accounts, register persistent authenticators, automate enumeration/download of SharePoint content (notably from IP 179.43.185.230 with user-agent 'python-requests/2.28.1'), and exfiltrate files to extort or sell; researchers note connections to ShinyHunters and BlackFile and recommend disabling device code authentication and restricting SharePoint to managed devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
