← BACK TO FEED
TAG

windows hello1 articles

Malware Can Hijack Windows Hello for Business Keys to Backdoor Your Microsoft Cloud Account

Researcher Dirk-jan Mollema has demonstrated that malware executing within a signed-in Windows session can silently exploit a victim's Windows Hello for Business key to authenticate to Microsoft Entra ID, without extracting the private key, requiring a PIN, or triggering biometric prompts. By treating the key as a FIDO2 passkey via WebAuthn, an attacker can obtain tokens, register a controlled device, acquire a Primary Refresh Token valid for 90 days, and potentially add further authentication methods — all without administrator privileges. No CVE or Microsoft advisory has been issued, no active exploitation has been reported, and Mollema recommends monitoring for device registrations and Windows Hello for Business sign-ins with an empty device ID as detection measures.

11 Aug 2026