Identity Briefing.
Identity AttacksAI & Agent IdentityAuthenticationStandards & RegulationVendor MovesCommunity & Events
identity attacks

A new group called Helix is using vishing and MFA abuse to empty SharePoint

Vishing, device-code phishing and MFA abuse, then it registers its own authenticator app. The second story this fortnight to start that way.

A new group known as Helix has emerged using identity-focused attacks to steal data from Microsoft 365 SharePoint environments.

According to research released by ReliaQuest, the group uses a combination of vishing calls, device-code phishing and MFA abuse to gain access to user accounts. Once inside, they quickly register their own authenticator app before searching SharePoint and extracting files for ransom.

ReliaQuest noted overlaps with the ShinyHunters and BlackFile data-extortion groups based on the techniques and infrastructure used, although researchers did not find a definitive connection.

Why identity teams should care

This is the second story in this issue where one of the attacker's first moves is to register a credential they control. The other is the campaign targeting Entra passkey enrolment.

Two unrelated actors, the same instinct. That is not a coincidence, it is a rational response to better authentication. If the front door is hard to force, the profitable move is to get issued a key of your own, quietly, and stop needing the front door at all.

Enrolment and recovery processes need to be protected just as carefully as the authentication method itself.

What to instrument

  • New authenticator registration as an alert, not a log line. With an owner, and a same-day response expectation.

  • Device-code flow usage. It exists for input-constrained devices. If it is being used from ordinary browsers, ask why.

  • Credential inventory per account. How many authenticators, registered when, and by which flow. If you cannot answer in under a minute, the account has no usable audit trail.

  • Bulk SharePoint access patterns. Extraction looks like search followed by download at a volume no human working normally would produce.

Source

Get Identity Briefing

Independent analysis for identity practitioners. Fortnightly and free.

Join identity architects, IAM leads and security leaders worldwide.