HomeSecurityWindows Hello for Business: Malware for persistent access to Entra ID

Windows Hello for Business: Malware for persistent access to Entra ID

Windows Hello for Business is at the center of a new class of attacks that allows malware to gain persistent access to Microsoft Entra ID accounts , even after a password reset. Security researchers have revealed that cryptographic keys associated with Windows Hello for Business can be exploited by attackers to bypass traditional account recovery methods, creating a worrying attack surface in enterprise environments. At the same time, the new NatJack class of attacks exposes critical weaknesses in NAT state management across multiple platforms.

See also: Certighost (CVE-2026-54121): PoC exploit to hijack Windows domains via AD CS

Windows Hello for Business malware vulnerability persistent access Entra ID

Security researcher Malcolm Stagg presented at Black Hat USA 2026 a new class of attacks called NatJack, which exploits NAT (Network Address Translation) to hijack active TCP sessions, forge DNS responses, reveal IP , and exhaust NAT. The research, conducted independently by SODIUM-24, challenges a fundamental assumption: that computers behind the same NAT cannot manipulate each other's connection state. As for Windows Hello for Business,

Two specific vulnerabilities have been assigned official CVE: CVE-2026-56181 with a CVSS score of 8.3 in Windows NAT used by Hyper-V, and CVE-2026-63913 with a CVSS score of 8.2 in Linux Netfilter conntrack. Stagg said he notified 13 vendors, tested 32 products and configurations, produced 95 test reports , and developed 7 proof-of-concept exploits — with all tested products showing vulnerabilities. In relation to Windows Hello for Business,

Windows Hello for Business: How malware gains persistent access

The central issue with Windows Hello for Business is rooted in a long-standing security dilemma in the world of passwordless authentication: once a device or session possesses a user's cryptographic key material, an attacker who compromises that session can often reuse the key for single sign-on and account recovery flows, without needing the PIN or biometrics. Researcher Dirk-jan Mollema documented that from a compromised user session, an attacker can use the WHfB to log in via WebAuthn, request tokens for new device enrollment, obtain a Primary Refresh Token (PRT) , and add additional authentication methods — as this action counts as fresh MFA.

Of particular concern is the abuse of the msDS-KeyCredentialLink in the directory, which has historically been used to create persistence that survives password changes. An attacker who enrolls a rogue passkey in a victim’s account gains a legitimate authentication method that is not automatically removed by a password reset or session revocation — unless the fake credential is explicitly deleted. This makes traditional incident response procedures inadequate if they are not accompanied by auditing and purging of enrolled authentication methods. The case of Windows Hello for Business

In recent incidents, the O-UNC-066 group has been abusing legitimate Entra passkey enrollment flows since April 2026 to gain persistent access that survives password resets and session revocations. In addition, there have been documented phone-based vishing attacks , where attackers trick users into enrolling an attacker-controlled passkey in their Microsoft Entra ID , creating persistent access that is resistant to MFA . Regarding Windows Hello for Business ,

See also: Zoom account takeover: Critical vulnerability CVE-2026-53412 in Windows clients

Windows Hello for Business: Malware for persistent access to Entra ID

NatJack and Windows Hello for Business: The technical analysis of the attacks

NatJack groups the attacks into five categories: UDP DNS hijacking , two variants of TCP/IP hijacking , victim IP/port disclosure, and denial of service . In the DNS attack , the attacker populates the NAT table with fake records to displace the victim's outstanding DNS record , then creates replacement records that point to the attacker. The legitimate DNS response is sent to the attacker instead of the victim, after which the attacker sends a fake response back to the victim.

For TCP , Stagg demonstrated downstream and upstream spoofing variants that remove and replace the victim's NAT entry to compromise the connection. In the upstream variant , the attacker and victim can be on different subnets and broadcast domains . Apple said it considers the behavior a known transport-layer limitation and not a vulnerability, saying it is considering additional hardening as a defense-in-depth measure . It is worth noting that the kernel change fixes the code flaw but only mitigates the broader downstream spoofing technique , increasing the attack complexity without fully addressing it.

NatJack also builds on previous NAT state manipulation research . An NDSS 2024 study demonstrated TCP hijacking via NAT mapping manipulation and found that 52 out of 67 tested routers were vulnerable, resulting in ten CVEs . This suggests that the vulnerability is not isolated but reflects a systematic weakness in the way many NAT implementations manage connection state.

Protection against Windows Hello for Business and NatJack attacks

There is no single patch for the broader NatJack. Organizations should apply available Windows and Linux for the CVEs , encrypt traffic even on internal networks, and use IP Source Guard where applicable. Separating untrusted workloads from trusted systems that share NAT is critical to limiting the attack surface.

To protect against Windows Hello for Business abuse, organizations should restrict passkey and authentication method enrollment so that only trusted devices, networks, or managed environments can add new authenticators . It is also essential to monitor and audit authentication methods for unexpected FIDO2 keys , passkeys , and device enrollments. Explicitly removing fake credentials — rather than relying solely on password resets or session revocation — is absolutely necessary, as these actions may not delete the attacker’s enrolled passkey .

See also: MedusaHVNC: The malware that hides in hidden Windows desktops

Windows Hello for Business: Malware for persistent access to Entra ID

Additionally, training helpdesk staff and users against phone registration fraud is critical, as attackers are abusing the registration process itself. Reviewing WHfB and Entra ID for unusual changes in device registration and authentication methods after suspicious connections is a key defensive practice. Finally, networks using Hyper-V NAT, conntrack, containers , or cloud NAT should verify update status and segmentation checks, as NatJack targets stateful management, and NAT should not be considered a reliable security boundary without additional protections.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS