Tech News

Copilot for Word Can Self-Replicate This AI Worm from Document to Document

An AI worm built on two Microsoft tools, Copilot and Word, has been revealed by Norwegian researcher Håkon Måløy. This new kind of worm contains no malicious code and hides in white text on a white background. Here is what we know about this threat.

Invisible text that only Copilot can see

The starting point of this technique is a booby-trapped Word document shared with the victim via email, Teams, and so on. When I say the document is booby-trapped, it is because at the end, the attacker has placed a malicious instruction written in JSON format. White text, white background, and a small font size. Invisible to a human reader, then.

This is where Copilot for Word comes in, as it strips out all formatting (color, font size) before sending the text to the language model. The hidden content is therefore invisible to humans but perfectly readable by the AI.

According to Håkon Måløy, the Norwegian researcher behind this discovery, the attacker only needs to share a malicious document with the victim to exploit this security issue. But what happens next? Let’s look at the researcher’s demonstration, built around a fictional company called Tfosorcim Ltd. (Microsoft spelled backward).

First, he demonstrated that Copilot could alter data: the AI cut all the financial figures in a quarterly report in half while it was being drafted, without mentioning it to the user. Then, and this is more worrying: self-propagation. Copilot acts like an AI worm because it copies the entire malicious instruction to the bottom of the document it has just produced, again in white text and size 8.

The report, now carrying the attack, becomes the new vector. A colleague reuses it as a source for their own document, and the cycle starts again, even though the original document is no longer present. Each time, the malicious instruction is reintroduced.

Beyond document sharing by email or Teams, the researcher also points to the "Edit with Copilot" feature in Work IQ mode. In this case, Copilot searches the victim’s OneDrive for relevant documents and selects the malicious file on its own. This is a good reminder that this operating mode was introduced with the Copilot Wave 3 updates.

The flaw still hasn’t been fixed....

Following this discovery, the researcher reported the security issue to Microsoft’s MSRC on March 6, 2026. He explained how to reproduce the attack, complete with a demo. Microsoft dragged its feet and eventually only a partial security fix was issued, with a patch on April 3, 2026. It neutralizes the original prompt wording.

Then, on July 14, 2026, Microsoft released a second patch to force the use of the GPT-5.5 model. The very next day, the researcher was able to reproduce the full exploit again, including propagation, simply by rephrasing the prompt and using GPT-5.6.

So, as of today, the security issue is still present because the attack works. One more reason to be wary of attachments and their origins. Find the researcher’s report on this page.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.