{"id":62597,"date":"2026-07-09T15:05:27","date_gmt":"2026-07-09T19:05:27","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62597"},"modified":"2026-08-31T02:21:33","modified_gmt":"2026-08-31T06:21:33","slug":"helix-device-code-phishing-vishing-group-attack-microsoft-365-sharepoint-data-extortion-reliaquest-shinyhunters-blackfile-mfa-abuse-social-engineering-cybersecurity-threat-identity-based-attack-recomm","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/helix-device-code-phishing-vishing-group-attack-microsoft-365-sharepoint-data-extortion-reliaquest-shinyhunters-blackfile-mfa-abuse-social-engineering-cybersecurity-threat-identity-based-attack-recomm\/","title":{"rendered":"Helix vishing group steals SharePoint data via device code phishing"},"content":{"rendered":"<p>A new data-extortion group tracked as Helix is combining voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to compromise Microsoft 365 accounts and steal data from SharePoint environments. The group, which cybersecurity firm <a href=\"https:\/\/www.reliaquest.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">ReliaQuest<\/a> believes may have emerged from the ShinyHunters and BlackFile ecosystems, represents an evolving identity-focused threat that targets organizations through <a href=\"https:\/\/overcentral.com\/en\/levi-strauss-data-breach\/\" title=\"Levi Strauss Discloses Data Breach After Social Engineering Attack\" data-iacss-internal=\"1\">social engineering<\/a> rather than traditional malware or exploitation of vulnerabilities.<\/p>\n<h2>How Helix Executes Its Vishing and Device Code Phishing Attacks<\/h2>\n<p>The initial attack vector is vishing, where threat actors call employees while impersonating a manager. In observed incidents, the caller used the manager&#8217;s name and, in some cases, caller ID spoofing to make the call appear legitimate. The goal of this social engineering is to convince the target to complete a <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/develop\/v2-oauth2-device-code\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">device code authentication<\/a> flow, which grants the attacker access to the victim&#8217;s Microsoft 365 account without requiring a password or bypassing MFA through a traditional phishing page.<\/p>\n<p>Once inside the account, Helix operators quickly register a new multi-factor authenticator app to establish persistence. They then enumerate SharePoint sites and bulk-download files. The stolen data is used for extortion: the group threatens to publish the data unless a ransom is paid, or sells it to other cybercriminals.<\/p>\n<h2>Technical Fingerprint: SharePoint Enumeration and Exfiltration<\/h2>\n<p>ReliaQuest researchers identified a consistent technical signature across Helix incidents. Automated enumeration and collection ran from the IP address <em>179.43.185[.]230<\/em> using the <code>python-requests\/2.28.1<\/code>codecodecodecodecode user-agent. The operator issued <em>contentclass:STS_Site<\/em> and wildcard (*) SharePoint searches to inventory all reachable content, then bulk-downloaded from the same IP and user-agent. This SharePoint exfiltration behavior is described as the group&#8217;s most reliable technical fingerprint.<\/p>\n<h2>What Is Device Code Phishing and Why Is It Effective?<\/h2>\n<p>Device code phishing is an attack technique that abuses the device code authorization flow used by Microsoft 365 and other identity platforms. In this flow, a user is presented with a code and directed to enter it on a separate device to authenticate. The attacker tricks the target into entering the code on a legitimate Microsoft login page, but the attacker controls the session. This method bypasses many traditional MFA protections because the user is authenticating directly with Microsoft&#8217;s own service. The highest-impact defensive measure against Helix attacks is to disable device code authentication where possible.<\/p>\n<h2>Links to ShinyHunters and BlackFile Data Extortion Groups<\/h2>\n<p>ReliaQuest assessed that Helix likely emerged from the ShinyHunters and BlackFile data extortion groups, though no definitive connection was established. The social engineering playbook is nearly identical to ShinyHunters: vishing, employee impersonation, targeting Microsoft 365, and stealing SharePoint data. Additionally, Helix uses the NICENIC registrar, which has been observed in past ShinyHunters campaigns.<\/p>\n<p>Regarding BlackFile, one Helix attack used an exfiltration IP address in the same autonomous system (AS 51852) that hosted a confirmed BlackFile IP address, suggesting shared infrastructure. BlackFile ceased operations in April, and Helix emerged <a href=\"https:\/\/overcentral.com\/en\/sharepoint-vulnerability-active-exploit\/\" title=\"SharePoint Vulnerability Exploited Shortly After PoC Release\" data-iacss-internal=\"1\">shortly after<\/a>, which may indicate a continuation of the extinct operation. ReliaQuest also noted Pink and Redact as potential successors in the same ecosystem.<\/p>\n<p>Recent victims linked to the ShinyHunters ecosystem include Medtronic, Nissan, NAIC, Kodak, Infinite Campus, and Nottingham University, all of which confirmed data breaches previously claimed by ShinyHunters.<\/p>\n<h2>Recommended Defenses Against Helix and Similar Identity-Based Attacks<\/h2>\n<p>Organizations should treat device code authentication as a high-risk feature and disable it wherever business requirements allow. Additional defensive measures include restricting SharePoint access to managed devices only and blocking authentication attempts from newly registered domains, which Helix typically uses in its attack infrastructure. Security teams should also monitor <a href=\"https:\/\/overcentral.com\/en\/for-the-stars-space-exploration-game-78319\/\" title=\"For The Stars Reveals Vast Universe to Explore and Settle\" data-iacss-internal=\"1\">for the<\/a> <code>python-requests\/2.28.1<\/code>codecodecodecodecode user-agent combined with SharePoint enumeration patterns as a potential indicator of compromise.<\/p>\n<h2>What Affected Organizations Should Do Now<\/h2>\n<p>Organizations that suspect a Helix compromise should immediately audit all MFA registrations for unauthorized authenticator apps, revoke any device code authentication sessions, and rotate credentials for affected accounts. SharePoint audit logs should be reviewed for bulk download activity originating from unrecognized IP addresses. For organizations that cannot disable device code authentication entirely, implementing conditional access policies to restrict its use to trusted devices and locations is a critical mitigation step. Deploying a multi-layer endpoint protection solution with behavioral analysis capabilities can help detect the post-compromise enumeration activity that characterizes this threat.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new data-extortion group tracked as Helix is combining voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to compromise Microsoft 365 accounts and steal data from SharePoint environments. The group, which cybersecurity firm ReliaQuest believes may have emerged from the ShinyHunters and BlackFile ecosystems, represents an evolving identity-focused threat that targets organizations [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84233,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62597.png","fifu_image_alt":"Helix vishing group steals SharePoint data via device code phishing","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62597","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62597.png","fifu_image_alt":"Helix vishing group steals SharePoint data via device code phishing","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62597"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62597\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84233"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}