Skip to content
Back to Guavy Wire
Stocks

Malware Exploits Windows Hello for Business Keys for Persistent Access

Instruments
MSFT
Share

A researcher has discovered that malware can exploit Windows Hello for Business keys to gain persistent access to Microsoft Entra ID. According to Dirk-jan Mollema, an attacker with code execution in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.

Mollema demonstrated that this technique allows attackers to establish longer-term cloud access, register devices, obtain Primary Refresh Tokens (PRT), and add further authentication methods. This is possible even on TPM-backed systems, where the attacker does not need to extract private keys or recover PINs.

The researcher notes that this behavior is a consequence of how Windows Hello for Business works and has been left as-is by Microsoft. Mollema recommends monitoring unexpected device registrations and hunting for Windows Hello for Business sign-ins with an empty device ID, which can indicate malicious activity.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc