hacker-news · Crawled Aug 7, 2026

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

3 IoCs
Read original article ↗

AI Summary

Researcher Dirk-jan Mollema demonstrated a technique where malware running in a signed-in Windows session can abuse Windows Hello for Business keys to silently authenticate to Microsoft Entra ID, enabling persistent cloud access without extracting private keys or requiring administrator privileges. By leveraging WebAuthn, the attacker can request a signed assertion from the compromised endpoint and use it to obtain a Primary Refresh Token (PRT), register a new device, and bypass phishing-resistant authentication requirements. The technique exploits legitimate Windows ticketing behavior and does not require device-specific access, allowing attackers to establish long-term access to cloud resources under certain tenant policies.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
GitHub Repo dirkjanm/ROADtools Details →
Filename fido_assertion.ps1 Details →
Filename hellopoc.ps1 Details →