Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
AI Summary
Researcher Dirk-jan Mollema demonstrated a technique where malware running in a signed-in Windows session can abuse Windows Hello for Business keys to silently authenticate to Microsoft Entra ID, enabling persistent cloud access without extracting private keys or requiring administrator privileges. By leveraging WebAuthn, the attacker can request a signed assertion from the compromised endpoint and use it to obtain a Primary Refresh Token (PRT), register a new device, and bypass phishing-resistant authentication requirements. The technique exploits legitimate Windows ticketing behavior and does not require device-specific access, allowing attackers to establish long-term access to cloud resources under certain tenant policies.
AI-extracted · verify before operational use