# Microsoft Vibing — Microsoft-Store-Distributed GenAI Application Silently Captures Screenshots, Clipboard, Microphone Audio, and Active Window Titles via Azure Front Door WebSocket Beacon

> DoublePulsar (Kevin Beaumont) disclosed on 2026-04-23 that Vibing.exe — a Microsoft-signed GenAI application distributed through the official Microsoft Store — silently captures full-screen screenshots, clipboard contents, microphone audio, and active-window titles without user consent, enterprise governance, or disclosure in the Store listing. The binary is digitally signed by Yaoyao Chang of Microsoft GenAI Research Labs (Beijing), establishes Registry Run-key autostart persistence, and beacons telemetry to an Azure Front Door endpoint (vibing-api-ccegdhbrg2d6bsd7.b02.azurefd.net) over WebSockets to evade corporate proxy and TLS-inspection infrastructure. No CVE has been issued — this is a trust-chain / supply-chain governance failure in which spyware-equivalent collection TTPs ship through a trusted first-party distribution channel.

- **Published:** 2026-04-23T12:00:00Z
- **Last reviewed:** 2026-04-23T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0418
- **ID:** TL-2026-0418
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** RESOLVED
- **Actor:** Microsoft GenAI Research Labs (China)
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-04-23 Kevin Beaumont (DoublePulsar) published research revealing that Vibing.exe, listed in the Microsoft Store under the publisher ''Microsoft GenAI Research Labs'' and Authenticode-signed by Microsoft developer identity Yaoyao Chang (Beijing), behaves as a client-side surveillance agent against any Windows user who installs it. The application presents itself as a generative-AI productivity assistant, but post-install telemetry analysis shows it performs continuous, unattended collection of four sensitive data classes: (1) full desktop screen captures of the primary display (MITRE T1113), (2) system clipboard contents including copy-paste of passwords, tokens and PII (T1115), (3) microphone audio samples captured via the Windows Audio Session API even when the visible UI is minimised (T1123), and (4) the text of the currently focused window title, which leaks filenames, URLs, chat partners and document subjects (T1010-adjacent reconnaissance). 

Persistence is established at install time by writing a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run (MITRE T1547.001), ensuring Vibing.exe launches at every user logon without any visible UI prompt or Start-menu pin. The collected telemetry is serialised and pushed to a dedicated Azure Front Door hostname — vibing-api-ccegdhbrg2d6bsd7.b02.azurefd.net — over a persistent WebSocket (wss://) channel rather than traditional HTTPS POST. The WebSocket upgrade pattern (MITRE T1071.001 Application Layer Protocol: Web Protocols, combined with T1090 Proxy since Azure Front Door acts as a CDN fronting endpoint) defeats many enterprise TLS-inspection and DLP egress controls that apply policy to per-request HTTP transactions but treat long-lived upgraded connections as opaque tunnels. The fronted hostname also permits domain-fronting-style blending with legitimate Azure CDN traffic, so block-on-domain strategies are brittle.

The critical distinction from conventional malware is the trust chain: the binary carries a valid Microsoft Authenticode signature, was distributed through Microsoft''s own curated Store, passes SmartScreen, and typically inherits elevated trust under Windows Defender, AppLocker baselines, and many enterprise allow-lists that permit ''Store-delivered, Microsoft-signed'' binaries by default. Corporate endpoint controls, attestation chains, and zero-trust posture checks that rely on signer identity or Store provenance as a proxy for safety are therefore bypassed at the policy level rather than the technical level. For DLP programmes this is catastrophic: screenshot, clipboard, and audio capture are the canonical exfil channels DLP is designed to block, and here they originate from a Microsoft-signed binary beaconing to a *.azurefd.net host — both of which are on most organisations'' trust lists.

The incident also raises governance questions around Microsoft Store vetting and the provenance of first-party generative-AI tooling. The signer (Yaoyao Chang, Microsoft GenAI Research Labs, Beijing) is a legitimate Microsoft developer identity, suggesting the issue is an internal governance and transparency failure rather than a compromised certificate or counterfeit store listing. No privacy disclosure, EULA clause, or Store manifest declared the screenshot/clipboard/microphone capture behaviours. Enterprise defenders must treat Vibing.exe as data-exfiltration software regardless of its provenance until Microsoft issues an authoritative statement, signed-binary revocation, or Store takedown, and must apply compensating controls at the network and process-behavioural layers.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1204.002 User Execution: Malicious File
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1553.002 Subvert Trust Controls: Code Signing
- T1036.005 Match Legitimate Resource Name or Location
- T1010 Application Window Discovery
- T1082 System Information Discovery
- T1113 Screen Capture
- T1123 Audio Capture
- T1115 Clipboard Data
- T1119 Automated Collection
- T1071.001 Application Layer Protocol: Web Protocols
- T1090 Proxy
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service

## Sources

- [Microsoft Vibing — capturing screenshots and voice samples without governance (DoublePulsar, Kevin Beaumont)](https://doublepulsar.com/microsoft-vibing-capturing-screenshots-and-voice-samples-without-governance-6973c48f03a7)
- [MITRE ATT&CK T1113 Screen Capture](https://attack.mitre.org/techniques/T1113/)
- [MITRE ATT&CK T1123 Audio Capture](https://attack.mitre.org/techniques/T1123/)
- [MITRE ATT&CK T1115 Clipboard Data](https://attack.mitre.org/techniques/T1115/)
- [MITRE ATT&CK T1547.001 Registry Run Keys / Startup Folder](https://attack.mitre.org/techniques/T1547/001/)
- [MITRE ATT&CK T1071.001 Application Layer Protocol: Web Protocols](https://attack.mitre.org/techniques/T1071/001/)
- [MITRE ATT&CK T1090 Proxy](https://attack.mitre.org/techniques/T1090/)
- [Microsoft Store — Publisher / Store policy (background)](https://learn.microsoft.com/en-us/windows/uwp/publish/store-policies)
- [Azure Front Door overview (network context for beacon hostname)](https://learn.microsoft.com/en-us/azure/frontdoor/front-door-overview)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0418
