{"slug": "prompt-turns-microsoft-copilot-into-an-ai-worm", "title": "Prompt turns Microsoft Copilot into an AI worm", "summary": "A security researcher demonstrated how Microsoft Copilot for Word can be tricked into spreading a self-propagating prompt-injection AI worm by hiding JSON-formatted instructions as white text on a white background. The attack alters documents and embeds hidden prompts into new files, allowing it to spread through normal document-sharing workflows without macros or traditional malware. The researcher could still reproduce the full worm chain after Microsoft rolled out mitigations including upgrades to GPT-5.5 and 5.6 models, and the attack is characterized as an architectural weakness of current LLM systems.", "body_md": "A [security researcher has demonstrated](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/) how Microsoft Copilot for Word can be tricked into spreading a self‑propagating prompt‑injection “AI worm.” The attack silently alters documents and embeds its own hidden instructions into newly created files, allowing it to spread through normal document-sharing workflows without macros or traditional malware.\n\nThe technique allows an attacker to hide a JSON‑formatted prompt as white text on a white background inside a Word document. When someone asks Copilot for Word to draft or edit content based on that document, Copilot strips away the formatting, reads the hidden text, and treats the embedded instructions as part of the user’s request.\n\nCopilot then modifies the active document and appends the full malicious prompt as hidden white text. That new document becomes a new carrier. Anyone who later uses it as source material for Copilot triggers the same behavior, allowing the prompt injection to spread to more documents. Because the documents are created and edited by legitimate users, the attack can be difficult to trace.\n\nThe researcher could still reproduce the full worm chain even after Microsoft rolled out multiple mitigations, including upgrades to newer GPT‑5.5 and 5.6 models.\n\nAt the time of writing, there is no complete mitigation for this broader class of attacks across comparable large language model (LLM)‑based products. It’s characterized as an architectural weakness of current LLM systems: attacker‑controlled content shares the same context window as trusted instructions. Attacks that exploit this behavior are known as [prompt injection attacks and may never be fixed](https://www.malwarebytes.com/blog/news/2025/12/prompt-injection-is-a-problem-that-may-never-be-fixed-warns-ncsc).\n\n## How to stay safe\n\nTreat documents from outside your organization as untrusted, especially if you plan to use them with Copilot for Word.\n\nReview any attached document before using it as Copilot source material, and carefully verify Copilot‑generated/edited documents before sharing or reusing them.\n\nIf you don’t use Copilot, you can disable it.\n\nMalwarebytes users can turn off Copilot under **Tools** > **System Tweaks** > **Miscellaneous**.\n\n**Or in Word itself:**\n\nFor individual users who don’t want Copilot in Word:\n\n- Open Word, go to\n**File**>** Options**>** Copilot**and clear the** Enable Copilot**checkbox, then restart Word.\n\n- In some versions of Word, the setting appears under\n**File**>** Options**>** General**in a Copilot section. In both cases, the key is unchecking the “Enable Copilot” setting.\n\nYou can also remove the Copilot icon from the ribbon by right‑clicking the ribbon, open the customization dialog, locate the Copilot/Assistance button, and removing it.\n\nAlternatively, you can limit Copilot’s role by following these instructions:\n\n- In Word, go to\n**File**>** Account**>** Account Privacy**>** Manage Settings**, and uncheck** Turn on optional connected experiences**. This reduces certain cloud‑powered AI features, including Copilot‑related functions that rely on those services. - In the Microsoft 365 Admin Center, under\n**Copilot**>** Settings**, set** Pin Microsoft 365 Copilot Chat**to** Do not pin Copilot chat in Microsoft 365 apps**so the chat pane doesn’t appear by default in apps like Word.\n\nThis doesn’t remove Copilot entirely or stop these attacks, but it does reduce its visibility and limits some of its cloud‑assisted functionality.\n\n**From reporting threats to removing them.**\n\nCybersecurity risks should never spread beyond a headline. Keep threats off your devices by [downloading Malwarebytes today](https://www.malwarebytes.com/for-home).", "url": "https://wpnews.pro/news/prompt-turns-microsoft-copilot-into-an-ai-worm", "canonical_source": "https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm", "published_at": "2026-07-30 15:35:30+00:00", "updated_at": "2026-07-30 15:52:51.675334+00:00", "lang": "en", "topics": ["ai-safety", "large-language-models", "ai-products"], "entities": ["Microsoft", "Copilot for Word", "Malwarebytes", "NCSC"], "alternates": {"html": "https://wpnews.pro/news/prompt-turns-microsoft-copilot-into-an-ai-worm", "markdown": "https://wpnews.pro/news/prompt-turns-microsoft-copilot-into-an-ai-worm.md", "text": "https://wpnews.pro/news/prompt-turns-microsoft-copilot-into-an-ai-worm.txt", "jsonld": "https://wpnews.pro/news/prompt-turns-microsoft-copilot-into-an-ai-worm.jsonld"}}