{"slug": "researcher-demonstrates-self-propagating-ai-worm-in-microsoft-copilot-for-word", "title": "Researcher demonstrates self-propagating AI worm in Microsoft Copilot for Word", "summary": "Norwegian AI researcher Hakon Maloy publicly disclosed a self-propagating prompt-injection attack on July 28 that can turn documents edited or generated by Microsoft Copilot for Word into carriers for further attacks. The proof-of-concept uses instructions concealed as white text on a white background that Copilot reads and propagates to new documents, potentially altering financial reports or other content. Microsoft deployed mitigations on April 3 and July 14 that blocked Maloy's original payloads, but he demonstrated that modified prompts could still reproduce the behavior, and said no customer-side step fully addresses the broader attack class.", "body_md": "[Hakon Maloy](https://github.com/haakom), a Norwegian AI researcher, publicly disclosed a self-propagating prompt-injection attack on July 28th that can turn documents edited or generated by Microsoft Copilot for Word into carriers for further attacks.\n\nThe [proof of concept](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/) uses instructions concealed as small white text on a white background. The text remains readable to Copilot because the assistant strips formatting before sending document contents to the underlying language model, according to Maloy. Copilot can then follow the hidden instructions, alter the document it is producing and paste the prompt into the output, where it remains concealed from the user. ([enklypesalt.com](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/))\n\nThat new document becomes the next carrier. If a colleague later uses it as source material in another Copilot-assisted drafting session, the hidden prompt can execute again and copy itself forward without the original malicious file being present. [International Cyber Digest summarized the demonstration on X](https://x.com/intcyberdigest/status/2082594518940221532?s=46) on July 29th.\n\nMaloy's example targeted the integrity of financial reports. A malicious market-analysis document instructed Copilot to halve figures in a draft and append the attack prompt to the resulting Word file. When that internally created report was used to produce a later report, Copilot repeated the numerical changes and propagated the prompt. Maloy withheld the exact payload while publishing the attack mechanism and disclosure timeline. ([enklypesalt.com](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/))\n\n### Microsoft mitigated payloads while the attack class persisted\n\nMaloy first reported the behavior to the Microsoft Security Response Center on March 6th. Microsoft acknowledged the report on March 9th and confirmed the behavior on March 31st, according to his disclosure timeline. Microsoft deployed an initial mitigation on April 3rd, and Maloy verified on April 9th that it blocked his original prompt wording. A modified prompt still reproduced the behavior that day. ([enklypesalt.com](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/))\n\nMicrosoft requested that disclosure be postponed on June 8th. A second mitigation, which Maloy described as an underlying model upgrade, went live on July 14th. He reproduced the worming behavior on July 15th and again on July 28th. The coordinated disclosure process lasted 144 days. ([enklypesalt.com](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/))\n\nMicrosoft told [The Register](https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588) that it had addressed the researcher's findings and uses multiple safeguards to block malicious instructions and keep Copilot aligned with user requests. Microsoft advised customers to install current updates, use layered security, treat unknown content cautiously and review AI-generated material before sharing it. ([theregister.com](https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588))\n\nMaloy drew a narrower distinction. Microsoft's changes blocked the specific payloads he submitted, he wrote, while altered prompts could still exploit the underlying path from untrusted source material to trusted model instruction. He said no customer-side step fully addressed the broader class when he published his findings. ([enklypesalt.com](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/))\n\n### A machine-learning researcher turns to Copilot's trust boundaries\n\nMaloy's background is in applied machine learning rather than conventional malware research. His [GitHub profile](https://github.com/haakom) describes him as an AI researcher and statistics hobbyist. In 2023, he completed a [doctoral thesis](https://www.sintef.no/en/publications/publication/2091444/) on neural representations for temporal data through the Norwegian University of Science and Technology and SINTEF Ocean. His earlier published work covered deep-learning systems for aquaculture and agricultural prediction. ([github.com](https://github.com/haakom))\n\nThe Word research is the third installment in Maloy's examination of what he calls \"context collapse\" in Microsoft 365 Copilot. Microsoft separately credited cases submitted by Maloy and other researchers in a [June 22nd discussion of AI-memory security](https://www.microsoft.com/en-us/security/blog/2026/06/22/guarding-ai-memory/). Microsoft described persistent memory as an expanded attack surface because poisoned information can influence behavior after its original context has disappeared. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/06/22/guarding-ai-memory/))\n\n### Ordinary documents become executable context\n\nThe attack does not depend on macros or traditional executable malware. Its carrier is text inside a business document, and the triggering event is a user or Copilot workflow selecting that document as context. Maloy says an attacker would not need access to the target's Microsoft 365 tenant. Delivery could occur through ordinary document-sharing channels such as Outlook, Teams, SharePoint or a compromised website. ([enklypesalt.com](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/))\n\nThe work follows [Morris II](https://arxiv.org/abs/2403.02817), a research project first published in 2024 that demonstrated self-replicating prompts across generative-AI email assistants. Maloy extended that concept into Word documents moving through routine enterprise collaboration, where an internally produced file can inherit trust as it passes between employees and organizations. ([arxiv.org](https://arxiv.org/abs/2403.02817))\n\nThat makes integrity the central risk. A poisoned document can quietly change figures, summaries or conclusions and then transmit the instructions responsible for those changes. The resulting file still appears to come from a legitimate employee and a familiar Microsoft workflow, making source provenance and model-made edits harder to reconstruct.\n\nMaloy advised Copilot users to treat externally sourced documents as untrusted, inspect files before adding them to Copilot and closely review generated or edited documents before reuse. Those controls add friction to the document-automation workflows Copilot is meant to accelerate, but they place a human checkpoint between untrusted text and a model that can rewrite and redistribute business records. ([enklypesalt.com](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/))", "url": "https://wpnews.pro/news/researcher-demonstrates-self-propagating-ai-worm-in-microsoft-copilot-for-word", "canonical_source": "https://runtimewire.com/article/microsoft-copilot-word-ai-worm-hakon-maloy", "published_at": "2026-07-30 00:36:44+00:00", "updated_at": "2026-07-30 00:56:14.031567+00:00", "lang": "en", "topics": ["ai-safety", "ai-products", "ai-research"], "entities": ["Hakon Maloy", "Microsoft Copilot for Word", "Microsoft Security Response Center", "The Register", "International Cyber Digest"], "alternates": {"html": "https://wpnews.pro/news/researcher-demonstrates-self-propagating-ai-worm-in-microsoft-copilot-for-word", "markdown": "https://wpnews.pro/news/researcher-demonstrates-self-propagating-ai-worm-in-microsoft-copilot-for-word.md", "text": "https://wpnews.pro/news/researcher-demonstrates-self-propagating-ai-worm-in-microsoft-copilot-for-word.txt", "jsonld": "https://wpnews.pro/news/researcher-demonstrates-self-propagating-ai-worm-in-microsoft-copilot-for-word.jsonld"}}