Malware Can Hijack Windows Hello Keys to Break Into Microsoft Cloud Accounts
Want more insights like this?
Security researcher Dirk-jan Mollema has uncovered a technique that lets malware abuse Windows Hello for Business cryptographic keys to authenticate into Microsoft Entra ID — no password, PIN, or fingerprint needed.
The attack works by exploiting an already-unlocked user session. Malware running in that session can trigger cryptographic signing operations through Windows interfaces, then use those signatures to request Primary Refresh Tokens or generate WebAuthn assertions — effectively impersonating the victim in Microsoft's cloud.
The resulting access tokens often lack a device identifier, letting attackers register new devices, add authentication methods, and establish persistence. Defenders should flag Entra ID sign-ins where the device ID is empty and watch for unexpected device registrations.
Source: Cybersecurity News