security1 publisher
A signed Windows binary can stand up a real Microsoft login and pocket the tokens
Huntress showed WWAHost.exe rendering attacker JavaScript with full WinRT access, driving a genuine login.microsoftonline.com prompt. The tokens survive MFA. The gate is Developer Mode.
Publishers:huntress.com
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives72
- Confidence55