Helix Data Extortion Group Targets SharePoint via Vishing and Device Code Phishing

Share:

A new criminal group called Helix is stealing company files from Microsoft SharePoint and demanding
payment to keep them private. The group phones staff while posing as their manager, tricks them into
approving a sign-in, then quietly downloads whole document libraries. No malware is used, so standard
antivirus tools will not catch it.

1.Campaign Timeline

ReliaQuest investigated multiple Helix intrusions that follow one consistent playbook across targets. BlackFile shut down in April 2026, and at least three successor brands, Pink, Redact, and now possibly Helix, appeared in under three months. Helix’s phishing domain oskeysync[.]com was registered through NICENIC, a registrar used in earlier BlackFile and ShinyHunters campaigns, and its exfiltration IP sits four addresses from a confirmed BlackFile IP on the same hosting provider. ReliaQuest assesses the ecosystem link as likely but not confirmed.

2. Targeting Profile

Helix researches each target before calling. Operators knew organisational charts and direct reports by name, and impersonated the target user’s manager using real contact details on caller ID. Targeting favoured high-visibility employees, including executives. Sign-in infrastructure was tailored per victim: residential proxies geo-matched to the victim’s city defeated impossible-travel alerts, and more than 15 residential IP addresses rotated against a single mailbox.

3. Attack Chain

Initial access

Operators call the target posing as their manager and walk them through entering a device code into Chrome. The flow captures a session token without the victim ever speaking a password, sidestepping Conditional Access.

Persistence

Within minutes of first sign-in, the operator registers a new MFA Authenticator app on the account from the same residential proxy. No malware, OAuth consent, or host changes: the only artifact is a legitimate-looking MFA registration.

Dwell and discovery

Dwell ranged from under an hour to over a week. Operators browsed SharePoint interactively or quietly read mail from rotating residential IPs; one intrusion exfiltrated from Box first before pivoting to SharePoint.

Exfiltration

Automated enumeration ran from 179.43.185[.]230 using the python-requests/2.28.1 user-agent, issuing
contentclass:STS_Site and wildcard searches to inventory all reachable content, then bulk-downloading from the same IP. This IP was never used for initial access.

Containment evasion

Cleanup was minimal: operators deleted phishing-awareness notification emails but left audit trails intact. In one case, the actor tried to re-register MFA and reset the password 30 to 40 minutes after the account was disabled.

4. Indicators of Compromise (IOCs)

  • IP: 179.43.185[.]230
  • IP: 179.43.185[.]226
  • DOMAIN: oskeysync[.]com

5. Recommendations

  • Disable device code authentication in Entra ID. If business needs prevent this, restrict the flow to managed devices and monitor for unusual device code requests.
  • Require managed, compliant devices for SharePoint, Exchange, and other sensitive SaaS applications through Conditional Access policies.
  • Alert on new MFA method registrations followed by SharePoint enumeration or bulk downloads. Treat contentclass:STS_Site searches from python-requests user-agents as hostile.
  • On confirmed compromise, revoke all sessions, disable the account, and reset the password across Entra ID and on-premises AD at the same time.
  • Block newly registered domains at proxy and DNS. Monitor for the IOCs and block them at their respective controls.

6. Sources

  • https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem/

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert