Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Dirk-jan Mollema, an Entra ID researcher, showed how malware can utilize the victim's Windows Hello for Business key to discreetly authenticate to Microsoft Entra ID if it is already operating in a signed-in Windows session.
Then, if tenant policies allow, the attacker can create longer-term cloud access, register a device under its control, acquire a Primary Refresh Token (PRT), and add other authentication methods.
The attacker does not retrieve the PIN, extract the private key, or initiate a biometric prompt on TPM-backed systems. Windows ticketing allows programs running as the user to request that Windows sign authentication data while the user is interactively logged in. It is not necessary to have administrator rights.
Code execution in the victim's signed-in session is ne...

