Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
According to a report from The Hacker News, researchers have discovered that malware can abuse Windows Hello for Business keys to achieve persistent access to Entra ID (formerly Azure Active Directory). The attack leverages the cryptographic keys used by Windows Hello for Business, which are typically stored in hardware security modules or TPMs, to maintain authentication even after a user changes their password or other credentials. This technique allows attackers to retain access to cloud resources and services without needing to re-authenticate, effectively bypassing standard security controls. The report does not specify which malware families are exploiting this, but it underscores a growing trend of attackers targeting authentication mechanisms to establish long-term persistence. The findings highlight the need for organizations to monitor for unusual authentication patterns and consider additional security measures beyond traditional password-based defenses.
This attack vector could allow malware to maintain persistent cloud access despite credential changes.