Cybersecurity researchers have discovered a new data extortion group called Helix that has been targeting companies by using user credentials rather than software vulnerabilities. Helix has been employing voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to target Microsoft 365 and steal data from the company’s SharePoint service.
According to the researchers at ReliaQuest, Helix has been attacking the company by first calling an employee and posing as their manager or another executive and tricking them into approving device code authentication and granting access to their Microsoft accounts. In some cases, the attackers used the manager’s name or changed the caller ID to disguise their location as the manager’s office. The attackers then register their own MFA Authenticator application on the victim’s account to ensure continued access to the Microsoft 365 platform even if the user changes their password.
The intruders then proceed to conduct reconnaissance on the SharePoint servers, enumerating and downloading all the available data, including documents, before the company detects the breach. The data is then used to demand ransom from the victim organization by threatening to publish the information if the company does not pay a certain amount of cryptocurrency. In some instances, the attackers sell the data to other bad-actor groups.
Researchers have noted that Helix’s automated SharePoint discovery has been one of the group’s most identifiable features. In one of the attacks, the attackers used automated search queries to find the SharePoint content before launching a large-scale data exfiltration campaign from the same IP address using a Python Requests user agent.
ReliaQuest researchers suspect that Helix may be linked to the ShinyHunters and BlackFile data extortion groups due to the similarity in attack techniques.
ReliaQuest researchers suspect that Helix may be linked to the ShinyHunters and BlackFile data extortion groups due to the similarity in attack techniques.
Although there is no conclusive evidence that the groups are connected, researchers have discovered similar infrastructure and tactics used by Helix and ShinyHunters.
Some of the organizations that have fallen victim to Helix include Medtronic, Nissan, the National Association of Insurance Commissioners (NAIC), Kodak, Infinite Campus, and the University of Nottingham. These companies were previously targeted by the ShinyHunters group and confirmed the breach on their websites.
Some of the organizations that have fallen victim to Helix include Medtronic, Nissan, the National Association of Insurance Commissioners (NAIC), Kodak, Infinite Campus, and the University of Nottingham. These companies were previously targeted by the ShinyHunters group and confirmed the breach on their websites.
In addition, ReliaQuest researchers discovered that one of the Helix’s exfiltration servers was hosted on an autonomous system previously used by the BlackFile infrastructure. Since BlackFile’s servers were shut down earlier this year, researchers suspect that Helix may have links to the BlackFile group or be an offshoot of the former group. However, other data extortion groups such as Pink and Redact may also be linked to BlackFile.
The campaign that targets Microsoft 365 is similar to the ShinyHunters ransomware attack in several ways, including impersonating employees, targeting the Microsoft 365 platform, stealing data from SharePoint servers, and using social engineering to trick employees into giving access to the company’s network. Researchers have also discovered that Helix uses the NICENIC domain registrar, which has been used in some of the ShinyHunters attacks.
Experts recommend that organizations disable device code authentication if possible and only allow managed devices to access the Microsoft SharePoint service. In addition, the company should monitor Microsoft 365 authentication activities and restrict all communications except those from trusted domains to protect their dat
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents
Read the original article:
