CyberNews
← Back to dashboard
IDENTITY The Hacker News

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Aug 7, 2026, 08:52 AM · by The Hacker News

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies

This development is consistent with broader industry trends, where threat actors increasingly reuse proven techniques and commodity tooling rather than investing in novel malware.

Security teams should review their detection rules, keep threat-intelligence feeds current, and validate that incident-response runbooks are tested before an incident occurs.

Source: The Hacker News