<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Malware Can Hijack Windows Hello Keys to Break Into Microsoft Cloud Accounts

Malware can exploit Windows Hello keys to access Microsoft Entra ID without passwords, raising security concerns for device registrations.
Content Team

Security researcher Dirk-jan Mollema has uncovered a technique that lets malware abuse Windows Hello for Business cryptographic keys to authenticate into Microsoft Entra ID — no password, PIN, or fingerprint needed.

The attack works by exploiting an already-unlocked user session. Malware running in that session can trigger cryptographic signing operations through Windows interfaces, then use those signatures to request Primary Refresh Tokens or generate WebAuthn assertions — effectively impersonating the victim in Microsoft's cloud.

The resulting access tokens often lack a device identifier, letting attackers register new devices, add authentication methods, and establish persistence. Defenders should flag Entra ID sign-ins where the device ID is empty and watch for unexpected device registrations.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo