<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Malware Can Hijack Windows Hello Keys to Break Into Microsoft Cloud Accounts

Malware can exploit Windows Hello keys to access Microsoft Entra ID without passwords, raising security concerns for device registrations.
Content Team

Security researcher Dirk-jan Mollema has uncovered a technique that lets malware abuse Windows Hello for Business cryptographic keys to authenticate into Microsoft Entra ID — no password, PIN, or fingerprint needed.

The attack works by exploiting an already-unlocked user session. Malware running in that session — with no admin rights required — can trigger cryptographic signing operations through Windows interfaces, then use those signatures to request Primary Refresh Tokens or generate WebAuthn assertions, effectively impersonating the victim in Microsoft's cloud.

Tokens issued through the WebAuthn path carry no device identifier, letting attackers register new devices, add authentication methods, and establish persistence. There is no patch and no CVE: Mollema describes the behaviour as a consequence of how Windows Hello for Business works, and it has been left as-is, so monitoring is the only mitigation.

Defenders should flag Entra ID sign-ins where the device ID is empty — expecting some false positives from legitimate incognito and non-SSO browser sessions — and watch for unexpected device registrations.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo