Malware Abuses Windows Hello Keys
A security researcher has discovered a new type of malware that can abuse Windows Hello for Business keys to gain persistent access to a user’s Entra ID. This malware, called NatJack, manipulates network address translation connection state to hijack active TCP sessions and spoof DNS responses. The researcher, Malcolm Stagg, presented his findings at Black Hat USA 2026, demonstrating the techniques across various network infrastructure devices.
The malware affects users who have enabled Windows Hello for Business, a feature that provides an additional layer of security for authentication. However, the malware can exploit this feature to gain unauthorized access to a user’s account. The attack works by manipulating the network address translation connection state, allowing the malware to hijack active TCP sessions and spoof DNS responses. This can lead to the disclosure of victim IP addresses and mapped ports, as well as the exhaustion of NAT tables.
To protect themselves from this type of malware, users should ensure that their systems and software are up to date with the latest security patches. Additionally, users can use free tools such as those found on ComputerScams.com to scan their systems for malware and other online threats. It is also important for users to be cautious when clicking on links or downloading attachments from unknown sources, as these can be used to spread malware.
Users can take a practical step to protect themselves by enabling two-factor authentication, which can help to prevent unauthorized access to their accounts even if their Windows Hello for Business keys are compromised. By taking these precautions, users can help to protect themselves from this type of malware and other online scams. Source: Read the original report