Helix threat group weaponises vishing and MFA abuse to drain SharePoint environments
Identity-based attacks are now the primary entry vector for enterprise data theft — and Helix, a newly identified threat group, represents a technically sophisticated iteration of that approach. Rather than exploiting unpatched software vulnerabilities, Helix targets the one layer most organisations still struggle to fully control: human and protocol trust.
The attack chain is structured around three techniques used in combination. Voice phishing (vishing) impersonates IT support or security teams to establish initial contact and create urgency. Device code phishing exploits the OAuth device authorisation flow to steal tokens without requiring the victim to enter credentials anywhere the attacker can intercept. MFA abuse then completes the bypass — in some cases exploiting MFA fatigue tactics, in others manipulating conditional access policies. The endpoint is SharePoint, where exfiltrated documents become leverage for extortion.
What Makes This Pattern Particularly Difficult to Block
Traditional perimeter controls don’t see most of this attack. The initial vishing call happens over the phone. The device code phishing flow is indistinguishable from a legitimate sign-in until the token is used. By the time SharePoint access occurs, it appears to come from an authenticated, MFA-compliant session. Behaviour analytics that look for impossible travel or unusual access volumes offer the best detection window — but only if they’re tuned to alert at volumes relevant to targeted exfiltration rather than mass scraping.
Operational Response for Microsoft 365 Environments
For ops and IT leaders running M365 estates, three controls reduce exposure significantly: restrict device code flow authentication at the Entra ID level (many organisations leave it enabled by default), implement Conditional Access policies that require managed or compliant devices for SharePoint access, and ensure the security operations team has an incident response playbook specifically for identity-led attacks — a generic ransomware response playbook is not designed for this threat type.
Helix is a reminder that the perimeter has moved. The identity plane is where the real battle is happening, and most enterprise security programmes are still calibrated for a world where the boundary is the firewall.