Researchers detailed how Microsoft nested app authentication (NAA), also called BroCI, can let an attacker who already holds a valid refresh token from a broker-capable Microsoft application exchange it for tokens to other apps and resources. The technique was shown against Azure and Entra ID workflows to retrieve Conditional Access Policy data, activate Privileged Identity Management roles, access Azure Key Vault secrets, and enumerate Intune devices by brokering requests through administrator portals. The write-up emphasized that MFA claims present in the original broker token can persist into downstream requests, potentially satisfying Conditional Access checks, and clarified that the method relies on refresh tokens, not access tokens.
A separate offensive analysis showed that VS Code Dev Tunnels can be abused for remote access by using authenticated GitHub or Azure/Entra ID tokens to enumerate tunnels, obtain connect-scoped JWTs, establish WebSocket relay sessions, and invoke MsgPack-based RPC methods for command execution and file operations on tunnel hosts. The author said credentials stored by VS Code can still be recovered by same-user processes despite Electron safeStorage, and released a Rust proof-of-concept called Ouroboros to interact with existing tunnels. Together, the research highlights how token theft, device-code phishing, and Microsoft token pivoting techniques such as FOCI/BroCI can extend access across cloud administration surfaces and developer remote-access infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
XPN InfoSec published an analysis of Microsoft Visual Studio Code Dev Tunnels, explaining how authenticated GitHub or Azure/Entra ID tokens can be used to enumerate tunnels, obtain connect-scoped JWTs, establish relay connections, and invoke RPC methods enabling remote command execution and file operations. The post also introduced a Rust proof-of-concept tool called Ouroboros and discussed persistence, lateral movement, and initial access implications.
SpecterOps published research on Microsoft nested app authentication (also called BroCI), describing how refresh tokens from broker-capable Microsoft applications can be exchanged for tokens to other applications and resources. The post detailed offensive use cases in Azure and Entra ID and clarified that the method uses refresh tokens only, not access tokens.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.