A newly discovered technique reveals how attackers can exploit Windows Hello for Business (WHFB) cryptographic keys without needing the victim's PIN or triggering biometric verification. Mollema’s research highlights that a non-exportable key remains accessible even when processes run in compromised user contexts. WHFB keys support authentication across Remote Desktop Protocol (RDP) sessions, allowing users authenticated on one device to access cloud services while connected to another Entra ID-joined device.

Mollema discovered that under specific circumstances, a low-privilege process in an authenticated session can access the Windows cryptographic interfaces needed to request signatures from a user's WHFB key. Windows Hello enhances security by enhancing account security.

Instead, it relies on previously cached authentication material described as a "ticket." By using the Passport Key Storage Provider and native cryptographic APIs, malware or an implant running as the user can request that the TPM-backed key sign authentication data. This research does not mention TPM key extraction but highlights the risk of session-level key misuse: an attacker who controls a logged-in Windows session can effectively "steal" hardware-backed keys for cloud authentication.

Utilizing in-browser data inspection from ANY.RUN enables faster response times to security incidents, enhancing your SOC effectiveness and reducing Mean Time To Respond (MTTR).