Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
News Source : Internet
News Summary
- Malware can silently use a victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.
- The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies permit.
- On TPM-backed systems, the attacker does not extract the private key, recover the PIN, or trigger a biometric prompt.
- The technique requires code execution in the victim's signed-in session.
Never miss a story from us, subscribe to our newsletter