A Microsoft-linked application called Vibing has been accused of covertly collecting sensitive user data, including screenshots, raw microphone audio, clipboard contents, window titles, application names, selected words, and keystroke-related activity, then transmitting it to a Microsoft-owned Azure tenant through an Azure Front Door endpoint. Reporting tied the software to Microsoft Research Asia and the VibeVoice project, with OSINT pointing to Microsoft-branded assets, a binary reportedly signed by Microsoft researcher Yaoyao Chang, and infrastructure associated with GenAI research activity in Beijing.
Researchers said the Windows app persists at login, begins collection without clear user prompts, and tags exfiltrated data with a per-device hardware GUID, raising concerns about device tracking, privacy, and undisclosed telemetry over WebSockets that may bypass some proxy controls. The reports also alleged the project bypassed Microsoft’s normal security, privacy, and AI governance reviews, that Microsoft Store privacy disclosures were misleading, and that internal and public complaints on GitHub were closed without remediation or a public response from Microsoft.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Additional reporting said OSINT linked Vibing.exe to Microsoft GenAI research activity in Beijing through a Microsoft-owned Azure tenant, Microsoft-branded assets, and a binary signed by a Microsoft researcher. It also alleged misleading Microsoft Store privacy disclosures and noted that Microsoft had not publicly responded despite GitHub issue reports and community pressure.
TechCrunch detailed the reported Morpheus infection chain, including telecom-assisted mobile data disruption, SMS lures, abuse of Android accessibility features, and a fake WhatsApp biometric prompt. The report said researchers believed the spyware was used against targets connected to political activism in Italy.
Kevin Beaumont reported that a GitHub project called Vibing, associated with Microsoft Research Asia and linked to VibeVoice, appeared to bypass Microsoft's normal governance and review processes. He alleged the Windows app persists at login, captures screenshots, clipboard contents, window and app metadata, selected words, keystroke-related data, and raw microphone audio, then sends the data with a hardware GUID to a Microsoft-owned Azure endpoint.
Osservatorio Nessuno published a report describing Android spyware it calls Morpheus, a surveillance tool allegedly delivered through fake phone update apps. The report linked the malware to Italian lawful interception company IPS based on infrastructure and code clues.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetechcrunch.com
Open sourcedoublepulsar.com
Open sourceosservatorionessuno.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.