logo

Recall: Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible.

ID: 327f759a-6723-53e2-aa64-07ee67569a99

STIX ID: report--327f759a-6723-53e2-aa64-07ee67569a99

Feed Name: DoublePulsar

Threat Score
75/100

Date Published: 2024-05-31

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

The author demonstrates that Microsoft’s Recall (Copilot) feature periodically captures screenshots, OCRs them to text, and stores that text in a locally accessible SQLite database; this data can be read and rapidly exfiltrated by malware or another local account. The report details design and deployment choices (enabled-by-default, storage path, exclusion gaps), shows proof of concept exfiltration and automation, and warns of large-scale privacy and breach risks since data persists even after deletion and can be harvested without the data processor’s involvement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.