LIVE · cybersecurity feed
Live wire

entra id

malwarehigh

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Researchers have discovered a method for malware to abuse Windows Hello for Business keys, enabling persistent access to Microsoft Entra ID. The technique allows malicious code running within a user's active session to silently authenticate using the victim's Hello for Business key, bypassing biometric or PIN prompts on TPM-backed systems. This can lead to the attacker registering their own device, obtaining a Primary Refresh Token, and potentially adding further authentication methods, even satisfying phishing-resistant authentication requirements.