Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Exploit Method Extracts Microsoft Entra Tokens Through Beacon

A novel exploit method leveraging Beacon Object Files (BOFs) has emerged, enabling attackers to extract Microsoft Entra (formerly Azure AD) tokens from compromised endpoints, even on non-domain-joined or BYOD devices. This technique sidesteps traditional…

A novel exploit method leveraging Beacon Object Files (BOFs) has emerged, enabling attackers to extract Microsoft Entra (formerly Azure AD) tokens from compromised endpoints, even on non-domain-joined or BYOD devices. This technique sidesteps traditional detection mechanisms and expands access to high-value targets, posing significant risks to enterprise cloud environments. PRT Extraction Limits on BYOD Devices Attackers often rely on extracting Primary Refresh Tokens (PRTs) from domain-joined devices to maintain access to Entra tenants. However, as detailed in Matthew Creel’s “Operator’s Guide to Device-Joined Hosts and the PRT Cookie,” PRT-based methods fail on non-domain-joined hosts. In such cases, attackers faced a roadblock: how to obtain refresh tokens without triggering alerts or requiring privileged access. TrustedSec’s recently released get_azure_token BOF (by Christopher Paschen) inspired a breakthrough. JUMPSEC’s TokenSmith tool being used with the “authcode” functionality, generating an authorization code flow URL (Microsoft Teams client ID). The tool initiates an Entra authorization code flow via the victim’s browser, captures the authorization code via a local listener, and exchanges it for tokens. However, its reliance on as a redirect URI limited targets to three FOCI-enabled apps: Azure CLI, Azure PowerShell, and Visual Studio Legacy. Authorization code returned in URL and window title Researchers discovered that repurposing Microsoft’s native client redirect URI ( bypasses the localhost restriction. This URI, designed for desktop/mobile apps, allows attackers to: Target high-value FOCI apps like Microsoft Teams, Copilot, and Edge. Extract authorization codes from browser window titles using the GetWindowTextA API. Exchange codes for tokens without relying on easily monitored localhost redirects. Technical Breakdown: How the Exploit Works BOF Execution: The attacker’s Beacon sends a command to launch a browser with a crafted Entra authcode URL. Code Capture: After the victim authenticates, the authorization code appears in the browser’s window title. Token Exchange: The BOF extracts the code and requests access/refresh tokens, which are exfiltrated to the attacker. Example Command: beacon> entra-authcode-flow 1fec8e78-bce4-4a03-aa91-5d88d2d7a83b “User.Read” (Uses Microsoft Teams’ client ID for stealth) Mitigation Recommendations Monitor Token Requests: Flag authcode flows for non-standard client IDs (e.g., Teams tokens issued to non-Teams processes). Restrict FOCI Consent: Audit and limit third-party app consent in Entra ID. User Training: Educate employees on phishing risks, as the attack requires initial browser access. Conditional Access: Enforce device compliance policies for sensitive apps. This technique highlights the growing sophistication of adversary-in-the-middle (AiTM) attacks against cloud identities. As JUMPSEC’s TokenSmith and TrustedSec’s tools gain traction, defenders must prioritize monitoring native OAuth flows and hardening Entra configurations. The proof-of-concept BOF and analysis are available on GitHub, underscoring the urgency for proactive defense measures. Setting Up SOC Team? – Download Free Ultimate SIEM Pricing Guide (PDF) For Your SOC Team ->

Based on reporting by GBHackers.

However, as detailed in Matthew Creel’s “Operator’s Guide to Device-Joined Hosts and the PRT Cookie,” PRT-based methods fail on non-domain-joined hosts.
Derek Vaughn · Thehackingpost
Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories