Threat reportSupply ChainTL-2026-0418
Microsoft Vibing — Microsoft-Store-Distributed GenAI Application Silently Captures Screenshots, Clipboard, Microphone Audio, and Active Window Titles via Azure Front Door WebSocket Beacon
Microsoft Vibing (TL-2026-0418), also tracked as Microsoft Vibing, is a high-severity supply-chain compromise, first published 2026-04-23. It is attributed to Microsoft GenAI Research Labs (China) with high confidence, affects Microsoft Microsoft Store (distribution channel), maps to 17 MITRE ATT&CK techniques (T1010, T1036.005, T1041), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 1Microsoft GenAI Research Labs
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0418
- Threat ID
- TL-2026-0418
- Also known as
- Microsoft Vibing, Vibing.exe, Microsoft GenAI Vibing, Vibing Installer
- Severity
- HIGH
- Status
- RESOLVED
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Microsoft GenAI Research Labs
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, legal, technology, defense, education, enterprise-general
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Microsoft Vibing
Malware and tooling: Custom WebSocket telemetry framework (Vibing proprietary)
How Microsoft Vibing works
DoublePulsar (Kevin Beaumont) disclosed on 2026-04-23 that Vibing.exe — a Microsoft-signed GenAI application distributed through the official Microsoft Store — silently captures full-screen screenshots, clipboard contents, microphone audio, and active-window titles without user consent, enterprise governance, or disclosure in the Store listing. The binary is digitally signed by Yaoyao Chang of Microsoft GenAI Research Labs (Beijing), establishes Registry Run-key autostart persistence, and beacons telemetry to an Azure Front Door endpoint (vibing-api-ccegdhbrg2d6bsd7.b02.azurefd.net) over WebSockets to evade corporate proxy and TLS-inspection infrastructure. No CVE has been issued — this is a trust-chain / supply-chain governance failure in which spyware-equivalent collection TTPs ship through a trusted first-party distribution channel.
On 2026-04-23 Kevin Beaumont (DoublePulsar) published research revealing that Vibing.exe, listed in the Microsoft Store under the publisher ''Microsoft GenAI Research Labs'' and Authenticode-signed by Microsoft developer identity Yaoyao Chang (Beijing), behaves as a client-side surveillance agent against any Windows user who installs it. The application presents itself as a generative-AI productivity assistant, but post-install telemetry analysis shows it performs continuous, unattended collection of four sensitive data classes: (1) full desktop screen captures of the primary display (MITRE T1113), (2) system clipboard contents including copy-paste of passwords, tokens and PII (T1115), (3) microphone audio samples captured via the Windows Audio Session API even when the visible UI is minimised (T1123), and (4) the text of the currently focused window title, which leaks filenames, URLs, chat partners and document subjects (T1010-adjacent reconnaissance).
Persistence is established at install time by writing a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run (MITRE T1547.001), ensuring Vibing.exe launches at every user logon without any visible UI prompt or Start-menu pin. The collected telemetry is serialised and pushed to a dedicated Azure Front Door hostname — vibing-api-ccegdhbrg2d6bsd7.b02.azurefd.net — over a persistent WebSocket (wss://) channel rather than traditional HTTPS POST. The WebSocket upgrade pattern (MITRE T1071.001 Application Layer Protocol: Web Protocols, combined with T1090 Proxy since Azure Front Door acts as a CDN fronting endpoint) defeats many enterprise TLS-inspection and DLP egress controls that apply policy to per-request HTTP transactions but treat long-lived upgraded connections as opaque tunnels. The fronted hostname also permits domain-fronting-style blending with legitimate Azure CDN traffic, so block-on-domain strategies are brittle.
The critical distinction from conventional malware is the trust chain: the binary carries a valid Microsoft Authenticode signature, was distributed through Microsoft''s own curated Store, passes SmartScreen, and typically inherits elevated trust under Windows Defender, AppLocker baselines, and many enterprise allow-lists that permit ''Store-delivered, Microsoft-signed'' binaries by default. Corporate endpoint controls, attestation chains, and zero-trust posture checks that rely on signer identity or Store provenance as a proxy for safety are therefore bypassed at the policy level rather than the technical level. For DLP programmes this is catastrophic: screenshot, clipboard, and audio capture are the canonical exfil channels DLP is designed to block, and here they originate from a Microsoft-signed binary beaconing to a *.azurefd.net host — both of which are on most organisations'' trust lists.
The incident also raises governance questions around Microsoft Store vetting and the provenance of first-party generative-AI tooling. The signer (Yaoyao Chang, Microsoft GenAI Research Labs, Beijing) is a legitimate Microsoft developer identity, suggesting the issue is an internal governance and transparency failure rather than a compromised certificate or counterfeit store listing. No privacy disclosure, EULA clause, or Store manifest declared the screenshot/clipboard/microphone capture behaviours. Enterprise defenders must treat Vibing.exe as data-exfiltration software regardless of its provenance until Microsoft issues an authoritative statement, signed-binary revocation, or Store takedown, and must apply compensating controls at the network and process-behavioural layers.
MITRE ATT&CK techniques used in TL-2026-0418
Discovery
T1010 Application Window Discovery; T1082 System Information Discovery
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1573.002 Encrypted Channel: Asymmetric Cryptography
Collection
T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection; T1123 Audio Capture
Initial Access
T1195 Supply Chain Compromise; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
Execution
T1204.002 User Execution: Malicious File
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
defense-impairment
Affected products and versions in Microsoft Vibing
- Microsoft — Microsoft Store (distribution channel)
Vulnerable versions: all current Windows 10 and Windows 11 Store client versions (trust-chain policy failure, not binary version) - Microsoft — Windows 10
Vulnerable versions: 22H2 and all supported builds where the Microsoft Store client is present - Microsoft — Windows 11
Vulnerable versions: 22H2; 23H2; 24H2; 25H2 - Microsoft GenAI Research Labs — Vibing
Vulnerable versions: all versions as shipped 2026-04-23 and earlier via Microsoft Store
Remediation for Microsoft Vibing
Immediate actions
- Block the Azure Front Door telemetry endpoint vibing-api-ccegdhbrg2d6bsd7.b02.azurefd.net at egress proxies, DNS sinkholes, and firewalls
- Inventory and uninstall Vibing.exe across the fleet via PowerShell: Get-AppxPackage -AllUsers *Vibing* | Remove-AppxPackage -AllUsers
- Remove HKCU\Software\Microsoft\Windows\CurrentVersion\Run value for Vibing on all affected hosts
- Temporarily disable Microsoft Store side-loading for non-admin users via Group Policy (Computer Configuration > Administrative Templates > Windows Components > Store > Turn off the Store application)
- Treat any endpoint that communicated with the C2 hostname as exposed — rotate credentials that could have been clipboard-captured during the exposure window
Workarounds
- AppLocker / WDAC rule to block any executable whose publisher is ''Yaoyao Chang'' or whose package family name starts with Microsoft.Vibing_
- Windows Privacy settings: revoke microphone access for all Microsoft Store apps until Store re-vetting completes
- Deploy Defender ASR rule ''Block executable content from email/webmail'' paired with custom indicator blocks for the known Vibing hashes
Longer-term hardening
- Deploy endpoint behavioural detection that alerts on unsolicited screen-capture, microphone-capture and clipboard-read APIs invoked by GUI-less background processes regardless of signer
- Introduce a Microsoft Store allow-list policy via Intune Managed Store so only vetted app IDs can install, blocking all Store-delivered apps not explicitly reviewed
- Add WebSocket upgrade inspection to TLS-intercepting proxies so *azurefd.net, *trafficmanager.net and similar fronted hostnames receive the same content-level scrutiny as plain HTTPS
- Update supplier/trust-chain risk policy to state that Microsoft Authenticode signing alone is NOT sufficient justification for exemption from DLP, EDR and egress-inspection controls
- Review all previously allow-listed Store apps for similar undisclosed collection behaviours
Weaknesses (CWE) in Microsoft Vibing
Timeline of Microsoft Vibing
- Vibing application listed on the Microsoft Store under publisher ''Microsoft GenAI Research Labs'' and made publicly installable to Windows 10 / 11 users.
- Kevin Beaumont (DoublePulsar) installs Vibing on an instrumented Windows host and begins behavioural, network, and binary analysis of the signed package.
- HKCU Run-key persistence for Vibing.exe confirmed; application relaunches silently on user logon with no UI prompt.
- Behavioural analysis confirms silent screen capture, clipboard read, microphone audio capture and active-window-title enumeration, all exfiltrated over WebSocket to vibing-api-ccegdhbrg2d6bsd7.b02.azurefd.net.
- Defender community begins circulating egress-block rules for vibing-api-*.azurefd.net and detection logic for screenshot/microphone API abuse by Store-signed binaries.
- Threadlinqs Intelligence ingests TL-2026-0418 under SUPPLY_CHAIN / HIGH; pipeline initiated for detection authoring and simulation.
- DoublePulsar publishes ''Microsoft Vibing — capturing screenshots and voice samples without governance'' detailing TTPs, IOCs, and the governance/trust-chain failure.
- As of 2026-05-29, the Microsoft Vibing.exe surveillance app is neutralized: Microsoft pulled it from the Store and disabled its Azure Front Door backend on 2026-04-24 (one day after Beaumont's disclosure), so beaconing is dead. The cause was an internal MS Research Asia governance bypass, not a persistent adversary; only residual local installs need cleanup.
Sources cited for Microsoft Vibing
- Microsoft Vibing — capturing screenshots and voice samples without governance (DoublePulsar, Kevin Beaumont)
- MITRE ATT&CK T1113 Screen Capture
- MITRE ATT&CK T1123 Audio Capture
- MITRE ATT&CK T1115 Clipboard Data
- MITRE ATT&CK T1547.001 Registry Run Keys / Startup Folder
- MITRE ATT&CK T1071.001 Application Layer Protocol: Web Protocols
- MITRE ATT&CK T1090 Proxy
- Microsoft Store — Publisher / Store policy (background)
- Azure Front Door overview (network context for beacon hostname)
Detection coverage for TL-2026-0418
As of 2026-04-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0418 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.