Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Image for article Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
News Source : Internet

News Summary

  • Malware can silently use a victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.
  • The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies permit.
  • On TPM-backed systems, the attacker does not extract the private key, recover the PIN, or trigger a biometric prompt.
  • The technique requires code execution in the victim's signed-in session.

Must read Articles