Malware Exploits Windows Hello Flaw for Persistent Cloud Access
A new vulnerability has been discovered in Windows Hello for Business keys, allowing malware to abuse them for persistent Entra ID access.
According to researcher Dirk-jan Mollema, malware running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.
This allows the attacker to establish longer-term cloud access and register a device it controls, obtaining a Primary Refresh Token (PRT) and adding further authentication methods where tenant policies permit.
The technique requires code execution in the victim's signed-in session and does not extract the private key or trigger a biometric prompt. Administrator privileges are not required.