In the current enterprise cybersecurity landscape, the emergence of new threat groups like Helix poses a growing challenge for protecting critical data. This group, specialised in stealing information from SharePoint environments, employs advanced social engineering tactics such as vishing (voice phishing), device code phishing, and abuse of multi-factor authentication (MFA) mechanisms. Their identity-focused approach —exploiting end-user trust— turns any organisation using SharePoint into a potential target. Faced with this reality, companies need to rethink their security strategies, integrating customised solutions that address both prevention and early detection.
Helix is not a conventional ransomware group. Its modus operandi relies on identity spoofing through phone calls (vishing), where attackers impersonate technical support staff or system administrators. Once they manage to trick the victim into revealing credentials or access codes, they use device code phishing to deceive the user into entering a fake code on a legitimate login page, thereby compromising the SharePoint session. Abuse of MFA —for example, MFA fatigue where multiple approval requests are sent— allows attackers to bypass the second security layer. All with a clear goal: extracting sensitive data stored in document libraries, lists, and collaboration sites.
From a technical perspective, the main vulnerability lies in excessive reliance on human factors and default MFA configurations not designed to withstand fatigue attacks. Organisations that have migrated their environments to the cloud, especially to Microsoft 365 with SharePoint Online, must assess whether their security policies are adapted to these new tactics. Implementing advanced cybersecurity services —such as penetration testing and awareness training— is essential to identify gaps before a group like Helix exploits them.
The impact of a successful attack can be devastating: loss of intellectual property, leakage of customer data, regulatory non-compliance (GDPR, UK Data Protection Act), and reputational damage. Moreover, SharePoint is often the central repository for critical documents, from contracts to financial reports, making it a very lucrative target. To mitigate these risks, companies cannot settle for generic solutions; they require custom software applications that strengthen authentication, monitor anomalous behaviour, and automate incident responses.
This is where companies like Q2BSTUDIO, specialised in software development and emerging technologies, provide a differential value. By designing custom applications, it is possible to integrate additional security controls directly into the SharePoint workflow, such as geolocation verification, pattern analysis using artificial intelligence, and implementation of dynamic MFA policies that activate upon suspicious behaviour. For example, an AI agents-based system can detect if a login originates from an unusual location or from an unregistered device, blocking the session before data exfiltration occurs.
Artificial Intelligence (AI) plays an increasingly relevant role in cybersecurity, not only for detection but also for automated response. AI agents can analyse SharePoint logs in real time, identify vishing patterns by analysing call and session metadata, and trigger containment protocols without human intervention. Q2BSTUDIO, with its expertise in AI and machine learning, offers intelligent agent solutions that integrate with cloud platforms like AWS or Azure, enabling centralised and scalable security orchestration.
Furthermore, continuous monitoring through Business Intelligence (BI) and Power BI tools provides complete visibility into the security posture. Custom dashboards can display metrics on vishing attempts, MFA success rates, unauthorised access, and attack trends, facilitating informed decision-making. Companies already using BI/Power BI solutions can extend their use to include cybersecurity indicators, turning raw data into actionable intelligence.
On the other hand, cloud infrastructure adoption (AWS, Azure) does not have to be a risk if properly configured. Q2BSTUDIO helps organisations migrate and manage their cloud environments with best security practices, applying zero trust architectures and network segmentation. In the case of SharePoint Online, it is recommended to enable conditional access policies, use resistant MFA (such as FIDO2), and limit device code usage only when strictly necessary. Additionally, periodic audits with custom pentesting tools —like those offered by Q2BSTUDIO— allow detection of vulnerabilities similar to those exploited by Helix.
Employee training is equally critical. Helix bases its success on deceiving the user; therefore, awareness campaigns simulating vishing and device code phishing attacks significantly reduce the likelihood of success. These simulations should be part of a continuous programme, supported by custom applications that record and analyse employee responses, identifying the most susceptible individuals for reinforced training.
In conclusion, the appearance of Helix underscores the need to adopt a holistic and customised approach to cybersecurity in collaborative environments like SharePoint. The combination of custom applications, artificial intelligence, BI monitoring, secure cloud infrastructure, and professional cybersecurity services —such as those provided by Q2BSTUDIO— enables companies not only to defend against current threats but also to anticipate future ones. Investing in a security strategy tailored to identity-based tactics is the best investment to protect the most valuable asset: data.




