Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Researcher Dirk-jan Mollema demonstrated that malware running in a logged-in Windows session can abuse Windows Hello for Business keys to authenticate silently to Microsoft Entra ID, enabling persistent cloud access without requiring admin privileges or extracting private keys. This technique leverages Windows ticketing and WebAuthn to request authentication on a compromised device, allowing attackers to register new devices, obtain refresh tokens, and bypass some conditional access controls, exposing limits in phishing-resistant authentication methods. Mollema has released proof-of-concept scripts and recommends monitoring for unexpected device registrations to detect such abuse.

https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top