216.73.217.24

A New Name in the Data Extortion Ecosystem?

· Published 23/07/2026 17:25

Export JSON

Essential information

Published
23/07/2026 17:25
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
blackfile data extortion device code phishing identity-based attacks mfa abuse sharepoint exfiltration shinyhunters vishing
Related entities
4 indicators, 4 observables, 1 intrusion sets (apt)

Description

A group called Helix has been identified conducting multi-target campaigns using , , and automated SharePoint exfiltration. The group likely emerged from the and ecosystem after shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.

External references