Helix is a recently identified data-extortion threat actor focused on identity-driven intrusions into Microsoft 365 environments, particularly SharePoint. The group relies on social engineering and cloud authentication abuse rather than traditional malware deployment, making its operations comparatively low-artifact and difficult to detect through endpoint-centric controls alone. Helix commonly initiates attacks with voice phishing, including impersonation of managers or other trusted internal contacts, and then coerces victims into completing device code phishing flows to grant access to their Microsoft 365 accounts. Observed tradecraft indicates the actor abuses authenticated cloud sessions instead of stealing passwords directly in every case. After initial access, Helix rapidly establishes persistence by registering a new MFA authenticator on the compromised account, then conducts discovery across email and SharePoint before moving to collection. A defining operational pattern is manual reconnaissance followed by automated SharePoint enumeration and bulk exfiltration. SharePoint appears to be the actor’s primary source of high-value corporate data, and theft from SharePoint is the strongest reported technical fingerprint associated with the group. Helix has also been observed using residential proxy infrastructure geolocated near victims and rotating source addresses to reduce the likelihood of anomalous sign-in detections. In some incidents the actor moved from initial access to large-scale data theft in under an hour, while other cases involved longer dwell times with quieter reconnaissance. Helix is assessed to be a data-extortion actor rather than a ransomware operator, with stolen information used for extortion and potentially resale. Reporting has noted overlaps in infrastructure, social-engineering playbooks, and post-compromise behavior with the ShinyHunters and BlackFile ecosystems, and possible continuity with successor clusters that emerged after BlackFile’s shutdown. However, any direct attribution link remains unconfirmed. Helix should therefore be understood as a distinct but possibly ecosystem-adjacent extortion actor operating within the broader 2025–2026 trend of malware-light, identity-centric attacks against cloud collaboration platforms. Known aliases are limited, and Helix has been publicly tracked under the name Helix.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-extortion operations focused on stealing data from SharePoint environments using identity-centric intrusion methods.
Data extortion operations targeting Microsoft 365 users via vishing and device code phishing, followed by MFA re-registration, SharePoint discovery, and bulk cloud data exfiltration.
Data-extortion operations focused on compromising Microsoft 365/SharePoint environments via vishing, device code phishing, MFA app registration for persistence, SharePoint enumeration, and bulk data exfiltration for extortion or resale.
Data extortion campaign using vishing, device code phishing, MFA abuse, residential proxies, and automated SharePoint enumeration and bulk exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.