Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Exploits Windows Hello Keys to Access Entra ID

Malware Exploits Windows Hello Keys to Access Entra ID

Posted on August 7, 2026 By CWS

Malware Targets Windows Hello Keys for Unauthorized Access

Cybersecurity researchers have unveiled a novel technique whereby malware can manipulate Windows Hello for Business keys to authenticate to Microsoft Entra ID. This method allows attackers to gain cloud access without requiring the victim’s password, PIN, or biometric information.

Windows Hello for Business is a passwordless authentication solution that typically safeguards a user’s private key within the Trusted Platform Module (TPM) of a device. Users can access this key via a PIN, fingerprint, or facial recognition, making it relatively secure from external threats.

Understanding the Attack Methodology

Security analyst Dirk-jan Mollema discovered that malware could exploit Windows cryptographic interfaces to use these keys during an active user session. This process does not necessitate a fresh authentication prompt, such as a PIN or biometric request, due to cached login data utilized by Windows Hello.

Although attackers cannot directly extract a TPM-protected key, malware operating in an unlocked session can request cryptographic operations from Windows using the protected key. The signatures generated through these operations can then be leveraged in identity verification processes.

Implications for Microsoft Entra ID

One potential attack vector involves requesting a Primary Refresh Token (PRT), which is a critical component for single sign-on across Microsoft applications. A valid PRT can offer long-term access, making it a prime target for cybercriminals aiming to maintain a foothold in cloud environments.

Previously, completing this attack required access to another device registered with Entra ID. However, the new research indicates that attackers can now treat the Windows Hello key as a FIDO2 passkey via the WebAuthn protocol, allowing them to authenticate to Microsoft Entra ID from a different device.

Security Recommendations for Organizations

The absence of a device identifier in the resultant access tokens can be advantageous for attackers, enabling them to register new devices within Entra ID. They can then pursue actions like obtaining a PRT or adding new authentication methods.

Security teams should closely monitor Entra ID sign-in logs for any Windows Hello for Business authentications lacking device identifiers. While such instances may occur legitimately in scenarios like private browsing, they should be rare in enterprise settings.

Moreover, organizations are encouraged to investigate any unexpected device registrations, new authentication methods, or unusual token activities. Protecting active Windows sessions is vital, as the attack hinges on malware operating under the targeted user.

For enhanced security, integrating advanced threat detection tools into your Security Operations Center (SOC) can accelerate incident response and mitigate risks associated with such sophisticated cyber threats.

Cyber Security News Tags:Authentication, cloud security, Conditional Access, cyber threats, Cybersecurity, FIDO2, Malware, Microsoft Entra ID, passwordless authentication, PRT, SOC, threat detection, TPM, WebAuthn, Windows Hello

Post navigation

Previous Post: 800 Malicious npm Packages Spread Cross-Platform Malware
Next Post: macOS Malware Steals Crypto via ClickFix Attacks

Related Posts

Microsoft Defender XDR New Advanced Hunting Tables for Email and Cloud Protections Microsoft Defender XDR New Advanced Hunting Tables for Email and Cloud Protections Cyber Security News
UK Police Arrested Man Linked to Ransomware Attack That Crippeled European Airports UK Police Arrested Man Linked to Ransomware Attack That Crippeled European Airports Cyber Security News
Let’s Encrypt Temporarily Stops Certificate Issuance After Issue Let’s Encrypt Temporarily Stops Certificate Issuance After Issue Cyber Security News
OpenAI Delays Astra AI Model to Address Cybersecurity Risks OpenAI Delays Astra AI Model to Address Cybersecurity Risks Cyber Security News
GitGuardian Ends 2025 with Strong Enterprise Momentum GitGuardian Ends 2025 with Strong Enterprise Momentum Cyber Security News
Starbucks Data Allegedly Sold on Cybercrime Forum Starbucks Data Allegedly Sold on Cybercrime Forum Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark