In the ever-evolving landscape of cyber threats, the emergence of new data extortion groups like Helix is a constant reminder of the need for vigilance and adaptability. This article delves into the intricacies of the Helix group, its tactics, and the implications for organizations, offering a comprehensive analysis that goes beyond the surface-level details. From the initial discovery to the post-access behavior, we explore the group's strategies, the challenges they pose, and the defensive measures that can be implemented to mitigate the risks.
The Helix Group: A New Player in Data Extortion
The Helix group, identified by ReliaQuest, has been operating in the shadows, employing sophisticated techniques to exploit vulnerabilities in identity systems. What sets Helix apart is its focus on identity-based intrusion, a shift that is becoming increasingly common in the extortion landscape. Instead of relying on malware or creating obvious backdoors, the group uses valid sessions, legitimate MFA registration, and normal cloud services to stay under the radar.
One of the most striking aspects of the Helix group is its use of voice phishing and device code phishing. By persuading staff to enter device codes, the group gains access to valid session tokens without directly asking for passwords. This technique, combined with the spoofing of caller IDs and the knowledge of company reporting structures, makes the attacks highly credible and effective.
The Infrastructure and the Ecosystem
The infrastructure used by the Helix group is a key element in understanding its operations. The domain oskeysync[.]com, registered through NICENIC, is used for phishing with target-specific subdomains. This domain has appeared in earlier campaigns tied to BlackFile, ShinyHunters, and the wider Scattered Spider or The Com network. The reuse of infrastructure, including hosting links, further points to a fragmented ecosystem where personnel, methods, and supporting infrastructure overlap.
The proximity of the IP address used for exfiltration (179.43.185[.]230) to an IP tied to a confirmed BlackFile operation (179.43.185[.]226) is a significant detail. While it does not prove the same operators were involved, it adds to the picture of a closely aligned actor using the same playbook. The speed of fragmentation in the data extortion market means new names are appearing faster than many organizations can map them, making it crucial to focus on recurring methods rather than branding.
The Identity Route: A Shift in Extortion Cases
The attacks carried out by the Helix group highlight a wider shift in extortion cases toward identity-based intrusion. Instead of deploying malware or creating obvious backdoors, the operators use valid sessions, legitimate MFA registration, and normal cloud services to stay under the radar. The residential proxies used for sign-ins are geo-matched to the target's city, reducing the chance of triggering impossible-travel alerts. In one case, more than 15 residential IP addresses were rotated against a single mailbox during the dwell period, blending the activity into ordinary login noise generated by VPNs and mobile networks.
Defensive Steps: What Organizations Can Do
The single most effective defensive measure is to disable device code authentication, which was confirmed as the entry method in the Helix intrusions. Where that is not possible, organizations should restrict the feature to a narrow group of managed devices and watch for unusual device code requests. Limiting access to sensitive software-as-a-service applications such as SharePoint and Exchange to managed endpoints only would also block the use of unmanaged devices seen in the incidents reviewed, even after a session had been compromised.
Another recommendation is to block newly registered domains at the proxy or DNS layer. The phishing infrastructure tied to Helix was recently registered, and domain age filtering can catch the short-lived infrastructure often used in data extortion campaigns. Standard response steps such as password resets, session revocation, and account disabling generally work when applied quickly enough, but the operator tested containment within 30 to 40 minutes of an account being disabled by attempting to re-register MFA and reset the password.
Conclusion: A Call to Action
The emergence of the Helix group is a stark reminder of the need for organizations to stay vigilant and adaptable in the face of evolving cyber threats. By focusing on recurring methods rather than branding, and by implementing defensive measures such as disabling device code authentication and limiting access to sensitive applications, organizations can mitigate the risks posed by groups like Helix. As the data extortion landscape continues to evolve, the ability to adapt and respond quickly will be crucial in safeguarding against these sophisticated attacks.