Prompt injection turns Word documents into self-spreading worms

Researcher Hakon Maloy showed how hidden instructions in a Word file can alter Copilot output and copy themselves into new documents.

CSBadmin
2 Min Read

A Norwegian AI researcher has demonstrated a self-propagating worm that rides inside Word documents and hijacks Microsoft 365 Copilot workflows. Hakon Maloy’s proof of concept hides malicious instructions in a document that Copilot later uses as source material for a new file, such as a financial report.

The hidden instructions, inserted as small white text, tell Copilot to alter figures in the report and to copy the instructions into the finished document. When another employee adds that file to their own work, the cycle repeats, making the infection hard to trace. Maloy described it as one of the first public demonstrations of document-borne AI-worm self-propagation in a mainstream productivity suite.

Microsoft confirmed the research and said it uses defense-in-depth safeguards that block malicious instructions at multiple points. Maloy reported the issue to Microsoft’s Security Response Center in March and, after 144 days and two mitigation attempts that included a model upgrade, concluded no robust fix for the broader class exists.

Security analysts note the worm bypasses traditional controls: the document is not malicious on delivery, exfiltration runs through the user’s authenticated Copilot session, and no code executes on the endpoint. Maloy recommends treating externally sourced documents as untrusted and reviewing AI-generated content before it is shared, since no customer-side fix fully addresses the issue.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.