Malware Exploits Windows Hello for Business Keys for Persistent Access
A researcher has discovered that malware can exploit Windows Hello for Business keys to gain persistent access to Microsoft Entra ID. According to Dirk-jan Mollema, an attacker with code execution in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.
Mollema demonstrated that this technique allows attackers to establish longer-term cloud access, register devices, obtain Primary Refresh Tokens (PRT), and add further authentication methods. This is possible even on TPM-backed systems, where the attacker does not need to extract private keys or recover PINs.
The researcher notes that this behavior is a consequence of how Windows Hello for Business works and has been left as-is by Microsoft. Mollema recommends monitoring unexpected device registrations and hunting for Windows Hello for Business sign-ins with an empty device ID, which can indicate malicious activity.