Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

A researcher demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID, then establish persistent cloud access, register a device, and obtain a Primary Refresh Token.

Malware already running in a signed-in Windows session can silently abuse a victim’s Windows Hello for Business key to authenticate to Microsoft Entra ID, security researcher Dirk-jan Mollema demonstrated. This allows an attacker to establish persistent cloud access, register a device under its control, obtain a Primary Refresh Token (PRT), and add further authentication methods. The attack exploits the legitimate credential flow, enabling long-term compromise without triggering typical alerts.