National Cyber Warfare Foundation (NCWF)

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access


0 user ratings
2026-08-10 10:21:58
milo
Blue Team (CND) , Attacks
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.

The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.