logo

Microsoft Store App Vibing.exe Allegedly Harvested Screens, Audio, and Clipboard Content

ID: f3c52ef3-54bb-5b2d-bcd9-30c229ee118b

STIX ID: report--f3c52ef3-54bb-5b2d-bcd9-30c229ee118b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-05-05

Author: Abinaya

...
...

A Microsoft Store application named Vibing.exe is reported to operate as covert spyware: it auto-launches at login, captures base64-encoded desktop screenshots, raw microphone audio, clipboard contents, and application/window metadata tagged with a hardware GUID, and exfiltrates data to an Azure Front Door WebSocket endpoint. The executable is reportedly digitally signed and OSINT links it to Microsoft GenAI research labs, creating significant privacy, surveillance, and supply-chain concerns; indicators include vibing.exe, "Vibing Installer.exe", and vibing-api-ccegdhbrg2d6bsd7.b02.azurefd.net.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.