Live Cybersecurity News Ticker | Codekeeper

Malware Can Hijack Windows Hello Keys to Break Into Microsoft Cloud Accounts

Written by Content Team | Aug 8, 2026, 12:22:24 PM

Security researcher Dirk-jan Mollema has uncovered a technique that lets malware abuse Windows Hello for Business cryptographic keys to authenticate into Microsoft Entra ID — no password, PIN, or fingerprint needed.

The attack works by exploiting an already-unlocked user session. Malware running in that session can trigger cryptographic signing operations through Windows interfaces, then use those signatures to request Primary Refresh Tokens or generate WebAuthn assertions — effectively impersonating the victim in Microsoft's cloud.

The resulting access tokens often lack a device identifier, letting attackers register new devices, add authentication methods, and establish persistence. Defenders should flag Entra ID sign-ins where the device ID is empty and watch for unexpected device registrations.

Source: Cybersecurity News