All posts

AI worms can now spread through Copilot for Word documents

Manaal KhanAugust 9, 2026 at 9:16 PM4 min read

A security researcher has demonstrated that malicious instructions hidden in documents can spread automatically through Microsoft Copilot for Word, turning each affected document into a carrier that infects downstream files. The attack remains exploitable at publication, and Microsoft has no robust fix available after 144 days of coordinated disclosure.

The vulnerability works like this: an attacker plants hidden instructions in a document. When someone uses that document as source material for Copilot-assisted drafting, the AI interprets those instructions as part of the user's request. It then manipulates the output and copies the malicious payload into the new document. That document becomes a carrier. If anyone uses it with Copilot later, the cycle repeats without the original malicious file ever being present again.

144 days
The coordinated disclosure period with Microsoft, extended twice from the original 90 days
Advertisements

How the attack spreads through normal workflows

One Word Doc Can Infect the Next (Copilot AI Worm)

The researcher's proof-of-concept follows a realistic scenario. An employee downloads a market analysis from a compromised website. The document looks legitimate but contains hidden instructions. When the employee drafts a financial report using Copilot with that analysis as source material, the AI alters internal figures and embeds the attack payload in the new report.

The employee saves and shares what appears to be a normal internal document. A colleague later uses that report as source material for another Copilot-assisted draft. The instructions trigger again, alter the new document, and copy themselves forward.

This is among the first public demonstrations of document-borne AI worm self-propagation in a mainstream commercial productivity suite. Previous research, including the Morris II worm, showed similar propagation in email-assistant ecosystems. But this attack targets the document workflows that enterprises already depend on daily.

Why Microsoft hasn't fixed it

The disclosure builds on earlier research into Cross-Domain Prompt Injection Attacks. Parts 1 and 2 of the researcher's series showed how external inputs could influence Copilot responses and lead to confidentiality impacts. This third part extends the analysis from single-interaction compromise to propagation.

Microsoft attempted two mitigations during the disclosure period, including a model upgrade. Neither closed the vulnerability class. The researcher tested the attack with all current mitigations deployed and confirmed it still works.

The decision to publish without a fix was deliberate. "Defenders cannot reduce exposure to a risk they are unaware of," the researcher wrote. Withholding the existence of the vulnerability while it affects ordinary document workflows seemed worse than controlled disclosure at the class level rather than the specific payload level.

Advertisements

What enterprises can do now

Microsoft's guidance amounts to procedural caution rather than technical controls. Organizations should treat externally sourced documents as untrusted when using them with Copilot. Review any attached document before starting a Copilot generation or edit. Carefully review Copilot-generated or Copilot-edited documents before reusing, sharing, or distributing them.

These steps reduce exposure but do not eliminate the risk. The attack succeeds precisely because the malicious instructions are hidden and the resulting documents appear legitimate.

ℹ️

Logicity's Take

This vulnerability matters most to startups and enterprises that have woven Copilot into their document workflows. The self-propagating nature means one compromised source document from a vendor, partner, or public website can corrupt an entire chain of internal reports. Until Microsoft delivers a technical fix, the safest approach is to sandbox Copilot-assisted drafts: generate, review manually, then share. Competitors like Google's Duet AI face similar prompt injection risks, so this is an industry problem, not just a Microsoft problem.

Also Read
Cyera buys Oasis Security for $1B to police AI agents

Related context on enterprise AI security and the emerging market for agent oversight

The broader prompt injection problem

Prompt injection attacks are not new. But the self-replicating mechanism demonstrated here raises the stakes. Traditional malware requires some form of execution environment. Document-borne AI worms only require that someone use the document with an AI assistant that follows instructions from its context window.

The more enterprises rely on AI assistants to process documents at scale, the larger the attack surface becomes. A single compromised market report from a research firm, a poisoned template from a SaaS vendor, or a tampered contract from a partner could seed infections across an organization's entire document corpus.

The question now is whether Microsoft, or any vendor shipping AI-powered document tools, can solve this class of vulnerability without fundamentally limiting what their assistants can do.

ℹ️

Need Help Implementing This?

If you're evaluating Copilot deployment or need to audit your document workflows for AI-related risks, our team can help. Contact us at hello@logicity.in.

Source: Hacker News: Best

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.