Windows Hello for Business Flaw Lets Malware Hijack Cloud Logins
A security researcher has demonstrated a concerning attack technique affecting Windows Hello for Business, the passwordless sign-in feature many organisations use with Microsoft Entra ID (formerly Azure Active Directory). The research shows that malware already running on a signed-in Windows device can silently use the victim's Windows Hello for Business authentication key to log into Entra ID without needing the user's password or additional approval.
Once inside, the attacker can go further than a one-off breach. They can register their own device as trusted, obtain a Primary Refresh Token (a powerful credential that keeps a device signed into Microsoft cloud services), and, depending on the organisation's security settings, even add new authentication methods. This effectively gives attackers a long-term foothold in a company's cloud environment that can survive password resets and may be harder to detect than a typical stolen-credential attack.
This technique highlights a broader lesson: even strong, modern authentication methods can be undermined if the underlying device is already compromised by malware. Businesses relying on Windows Hello for Business and Entra ID should not assume passwordless login alone eliminates risk from endpoint infections.