맬웨어가 Windows Hello for Business 키를 이용해 Entra ID에 지속적으로 접근할 수 있는 취약점을 보여줍니다.
Dirk-jan Mollema 연구원은 맬웨어가 이미 사용 중인 Windows 세션 내에서 사용자의 Windows Hello for Business 키를 이용해 Microsoft Entra ID에 인증할 수 있음을 시연했습니다. 이 공격자는 클라우드에 대한 장기적인 접근을 설정하고, 자신의 장치를 등록하며, 주요 새로 고침 토큰(Primary Refresh Token, PRT)을 획득할 수 있습니다. 또한, 사용자의 테넌트 정책에 따라 추가 인증 방법을 설정할 수 있습니다.
Malware can abuse Windows Hello for Business keys for persistent access to Entra ID.
Researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. This allows attackers to establish longer-term cloud access, register a device they control, obtain a Primary Refresh Token (PRT), and add further authentication methods depending on tenant policies.