The world of data extortion is a complex and ever-evolving landscape, and the latest threat actor to emerge is the Helix group. This article delves into the tactics and techniques employed by Helix, shedding light on their unique approach to data extortion and the potential implications for organizations. From voice phishing to automated SharePoint data theft, the group's methods are sophisticated and highly targeted, making it crucial for businesses to understand and adapt their defenses accordingly.
One of the most striking aspects of the Helix group's operations is their focus on identity systems rather than malware. By persuading staff to enter device codes, they gain access to valid session tokens without directly asking for passwords. This subtle yet effective strategy highlights the importance of employee awareness and training in preventing such attacks. The group's ability to spoof caller IDs and manipulate company reporting structures further emphasizes the need for robust identity and access management practices.
The use of residential proxies for sign-ins is another intriguing tactic. By geo-matching these proxies to the target's city, the attackers reduce the risk of triggering impossible-travel alerts. This level of detail and customization showcases the group's dedication to maintaining a low profile and avoiding detection. The rotation of residential IP addresses against a single mailbox further blends the activity into ordinary login noise, making it even more challenging to identify and mitigate the threat.
The automated SharePoint collection process is a clear technical fingerprint of the Helix group. By using the python-requests/2.28.1 user-agent, they enumerate and download SharePoint material in bulk. This methodical approach to data collection and exfiltration is a key differentiator from other data extortion groups, and it underscores the importance of securing and monitoring SharePoint environments.
In terms of defense, ReliaQuest recommends several measures to mitigate the risks associated with the Helix group. Disabling device code authentication is a critical step, as it was the confirmed entry method in the Helix intrusions. Restricting this feature to a narrow group of managed devices and monitoring for unusual device code requests can significantly reduce the attack surface. Additionally, limiting access to sensitive SaaS applications to managed endpoints and blocking newly registered domains at the proxy or DNS layer can help prevent unauthorized access and data exfiltration.
The article concludes by emphasizing the need for organizations to stay vigilant and adapt their defenses to the evolving threat landscape. The links between Helix and established groups like BlackFile and ShinyHunters are significant, and the overlap in infrastructure, tradecraft, and timing should serve as a warning sign. By focusing on recurring methods rather than branding, organizations can better prepare for and respond to data extortion campaigns, ultimately safeguarding their valuable assets and sensitive information.