Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Exploits Windows Hello Keys to Access Entra ID

Malware Exploits Windows Hello Keys to Access Entra ID

Posted on August 7, 2026 By CWS

Malware Targets Windows Hello Keys for Unauthorized Access

Cybersecurity researchers have unveiled a novel technique whereby malware can manipulate Windows Hello for Business keys to authenticate to Microsoft Entra ID. This method allows attackers to gain cloud access without requiring the victim’s password, PIN, or biometric information.

Windows Hello for Business is a passwordless authentication solution that typically safeguards a user’s private key within the Trusted Platform Module (TPM) of a device. Users can access this key via a PIN, fingerprint, or facial recognition, making it relatively secure from external threats.

Understanding the Attack Methodology

Security analyst Dirk-jan Mollema discovered that malware could exploit Windows cryptographic interfaces to use these keys during an active user session. This process does not necessitate a fresh authentication prompt, such as a PIN or biometric request, due to cached login data utilized by Windows Hello.

Although attackers cannot directly extract a TPM-protected key, malware operating in an unlocked session can request cryptographic operations from Windows using the protected key. The signatures generated through these operations can then be leveraged in identity verification processes.

Implications for Microsoft Entra ID

One potential attack vector involves requesting a Primary Refresh Token (PRT), which is a critical component for single sign-on across Microsoft applications. A valid PRT can offer long-term access, making it a prime target for cybercriminals aiming to maintain a foothold in cloud environments.

Previously, completing this attack required access to another device registered with Entra ID. However, the new research indicates that attackers can now treat the Windows Hello key as a FIDO2 passkey via the WebAuthn protocol, allowing them to authenticate to Microsoft Entra ID from a different device.

Security Recommendations for Organizations

The absence of a device identifier in the resultant access tokens can be advantageous for attackers, enabling them to register new devices within Entra ID. They can then pursue actions like obtaining a PRT or adding new authentication methods.

Security teams should closely monitor Entra ID sign-in logs for any Windows Hello for Business authentications lacking device identifiers. While such instances may occur legitimately in scenarios like private browsing, they should be rare in enterprise settings.

Moreover, organizations are encouraged to investigate any unexpected device registrations, new authentication methods, or unusual token activities. Protecting active Windows sessions is vital, as the attack hinges on malware operating under the targeted user.

For enhanced security, integrating advanced threat detection tools into your Security Operations Center (SOC) can accelerate incident response and mitigate risks associated with such sophisticated cyber threats.

Cyber Security News Tags:Authentication, cloud security, Conditional Access, cyber threats, Cybersecurity, FIDO2, Malware, Microsoft Entra ID, passwordless authentication, PRT, SOC, threat detection, TPM, WebAuthn, Windows Hello

Post navigation

Previous Post: 800 Malicious npm Packages Spread Cross-Platform Malware
Next Post: macOS Malware Steals Crypto via ClickFix Attacks

Related Posts

Fake Notepad++ Mac Site Poses Cybersecurity Threat Fake Notepad++ Mac Site Poses Cybersecurity Threat Cyber Security News
AI-Driven Malware Exploits React2Shell Vulnerability AI-Driven Malware Exploits React2Shell Vulnerability Cyber Security News
SystemBC Malware: A Stealthy Threat to Enterprise Networks SystemBC Malware: A Stealthy Threat to Enterprise Networks Cyber Security News
New Phishing Attack Targeting PyPI Maintainers to Steal Login Credentials New Phishing Attack Targeting PyPI Maintainers to Steal Login Credentials Cyber Security News
New BOF Tool Exploits Microsoft Teams’ Cookie Encryption allowing Attackers to Access User Chats New BOF Tool Exploits Microsoft Teams’ Cookie Encryption allowing Attackers to Access User Chats Cyber Security News
Android Zero-Interaction Bug Sparks Urgent Security Patch Android Zero-Interaction Bug Sparks Urgent Security Patch Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark