In the ever-evolving landscape of cyber threats, the emergence of new data extortion groups like Helix is a constant reminder of the need for vigilance and adaptability. As an expert in the field, I find the tactics employed by such groups particularly intriguing, especially when they mirror those of more established players like BlackFile and ShinyHunters. This article delves into the intricacies of the Helix group, its methods, and the implications for organizations worldwide.
The Helix Group: A New Player in Data Extortion
The discovery of the Helix group by ReliaQuest sheds light on a previously unreported data extortion campaign. What sets Helix apart is its use of voice phishing, device code phishing, and automated SharePoint data theft, all of which are part of a broader pattern seen across multiple incidents. This suggests an organized operation rather than isolated intrusions, which is a worrying trend in the fast-changing data extortion landscape.
Infrastructure and Branding: A Fragmented Ecosystem
One of the most striking aspects of the Helix campaign is its reuse of infrastructure. The domain oskeysync[.]com, registered through NICENIC, has been linked to earlier campaigns tied to BlackFile, ShinyHunters, and the Scattered Spider or The Com network. This proximity in infrastructure, tradecraft, and timing raises questions about the relationships between these groups. It's possible that Helix is another offshoot or a closely aligned actor using the same playbook, which is a common trend in the data extortion market.
Identity-Based Intrusion: A Shifting Trend
The attacks carried out by Helix highlight a broader shift in extortion cases toward identity-based intrusion. Instead of deploying malware or creating obvious backdoors, the operators used valid sessions, legitimate MFA registration, and normal cloud services to stay under the radar. This approach, which relies on residential proxies geo-matched to the target's city and automated SharePoint collection, serves as a clear technical fingerprint. It suggests a deliberate separation between the sign-in stage and the collection stage, which is a worrying trend for organizations.
Defensive Steps: What Organizations Can Do
The single most effective defensive measure against the Helix group is to disable device code authentication, which was confirmed as the entry method in the Helix intrusions. Organizations should also restrict the feature to a narrow group of managed devices and watch for unusual device code requests. Limiting access to sensitive SaaS applications such as SharePoint and Exchange to managed endpoints only can also block the use of unmanaged devices seen in the incidents reviewed. Blocking newly registered domains at the proxy or DNS layer can also help catch the short-lived infrastructure often used in data extortion campaigns.
Conclusion: The Need for Vigilance and Adaptability
The emergence of the Helix group serves as a stark reminder of the need for vigilance and adaptability in the face of evolving cyber threats. As an expert in the field, I believe that organizations must pay less attention to the branding of specific groups and more to recurring methods. The speed of fragmentation in the data extortion market means that new names are appearing faster than many organizations can map them. By staying informed and implementing defensive steps, organizations can better protect themselves against the Helix group and other emerging threats.