Security researcher: a Word doc can turn Copilot into an AI worm spreader
Security researcher Håkon Måløy has detailed a prompt-injection attack in which hidden instructions inside a Word document cause Microsoft Copilot to manipulate the file being edited and copy the malicious payload into new documents. The attack uses JSON-formatted data and can create a self-propagating chain of infected files — effectively an AI worm. Måløy warns that agentic AI applications are especially vulnerable to such exploits.
Full text
Though I write a fair amount about AI agents, I do not use them. This is because agentic AI applications often introduce a more than medium-sized headache in terms of cybersecurity. For instance, one security research recently explained how a Word Doc could be leveraged to get Copilot to spread an AI worm.
AI researcher Håkon Måløy breaks down how the attack in a recent blog post , writing, "An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier."
The attack involves a "JSON-formatted malicious prompt." From this prompt injection of JSON-formatted data, a chain reaction wriggles into action. The worm replicating through 'carrier' documents scooped up in further Copilot-assisted workflows—the original document that kicked off the whole thing doesn't even need to be present. Worse still, the attacker needs no special access, they just need to "share a malicious document with the victim."
This isn't the first AI agent cybersecurity threat we've seen. For instance, back in February Meta's AI safety director recalled how she ' had to RUN to my Mac mini like I was defusing a bomb ' when her OpenClaw AI decided to start deleting all of her emails. Last year, Replit's LLM-based coding assistant deleted a dev's entire database during a code freeze . But on the subject of Copilot PCs more broadly, cybersecurity experts warn that Windows Recall may be far from secure when it comes to protecting your personal information .
As for the Copilot AI worm, Måløy first disclosed the vulnerability to Microsoft back in March, though the attack is still reproducible at time of writing. Måløy offers a detailed disclosure timeline, and explains, "Two mitigation attempts, including a model upgrade, did not close [this] class [of vulnerability]."
(Image credit: FromSoftware) As such, Måløy's blog post only broadly describes the type of attack possible, rather than going into detail about the hidden prompt that triggers the AI worm. The way this prompt is hidden doesn't require anything fancy, though, and may even be familiar to those who have ever wanted to catch someone out for using AI; at minimum, an attacker could format the malicious prompt as tiny white text on a white background.
"The prompt can be rendered as white text on a white background and in a small font size to conceal it from the victim," Måløy elaborates, "Since Copilot for Word strips all text formatting like color and font size before passing the text into the underlying Large Language Model (LLM), this text remains fully readable to Copilot even though the victim cannot see it. The attack can be further concealed by embedding it in a seemingly benign document with task-relevant text."
Long story short, this is a fairly low effort, hard to trace attack without sufficient mitigation currently in place. Cybersecurity and antivirus company Malwarebytes offers a few tips on how to stay safe from this class of attack , including disabling Windows Copilot in Word or simply ditching the AI agent altogether.
Personally, I think Måløy's closing thought sums up the security risk of AI agents nicely: "Any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model’s context will result in compromise at some rate."
Similar stories
💻 Technology
Word worm hijacks Microsoft Copilot to silently spread poisoned docs
TechRadar · 3d ago
💻 Technology
AI worms can self-propagate through Microsoft Copilot for Word via documents
Hacker News · 6d ago
💻 Technology
Nine top AI tools can be exploited to build massive botnets via prompt injection
Ars Technica · 28d ago
Similar stories
💻 Technology
Word worm hijacks Microsoft Copilot to silently spread poisoned docs
TechRadar · 3d ago
💻 Technology
AI worms can self-propagate through Microsoft Copilot for Word via documents
Hacker News · 6d ago
💻 Technology
Nine top AI tools can be exploited to build massive botnets via prompt injection
Ars Technica · 28d ago
Should companies pause agentic AI deployments until security vulnerabilities are resolved?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!