Helix has surfaced as a fast-moving data extortion group that targets Microsoft 365 users through phone scams and cloud-focused phishing instead of traditional malware drops. Attackers are after access first, then large volumes of corporate files, with SharePoint libraries becoming a central prize in multiple incidents. The campaign stands out because it leans on identity abuse rather than noisy ransomware behavior. Victims can be talked into entering a device code, giving the threat actor a valid session that bypasses many of the warning signs defenders expect from password theft. Analysts at ReliaQuest said the activity reflects a broader shift toward identity-driven intrusion chains, and they tied Helix to a repeatable...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!