Copilot Word AI Worm Can Spread Hidden Prompts Between Documents

Brendan Smith
Brendan Smith - Cybersecurity Analyst
8 Min Read
A chain of documents carrying a hidden prompt through Microsoft Copilot for Word.
A hidden instruction can become part of a new Copilot-generated document and remain dormant until that file is used as AI context.

A security researcher has demonstrated a Copilot Word AI worm: a hidden instruction in one document can direct Microsoft Copilot to alter values and copy the instruction into a newly generated or edited file. That output can then become another carrier if someone later gives it to Copilot as source material.

The important boundary is easy to miss. The published test did not show a document infecting a computer merely because someone received, previewed, or opened it. The trigger occurred when the file entered Copilot’s working context—because a person attached it or because Microsoft 365 Work IQ selected it as a relevant source. The finding concerns AI-assisted document integrity, not a conventional Word macro virus.

What the researcher demonstrated

Håkon Måløy published the test on July 28 and updated it on July 30, 2026, after coordination with the Microsoft Security Response Center. The proof of concept placed an instruction where a reader was unlikely to notice it. When Copilot processed the document, the instruction asked the assistant to change information and reproduce the same hidden text in the output.

The result is a propagation loop: a source document influences an AI-generated report, the report preserves the instruction, and a later Copilot task can activate it again. Måløy reported that Microsoft mitigations blocked his original payloads, but he could still reproduce the broader behavior with modified prompts at publication time. That makes this a security design problem worth tracking, while not proving that every Copilot prompt can bypass current controls.

Situation What it means
A person receives or opens the document normally No trigger was demonstrated. The hidden text is inert unless an AI system processes it as instructions or context.
The person attaches the document to Copilot The file enters the exposure boundary, and its hidden content may influence the requested task.
Work IQ automatically selects the file as relevant The same exposure can occur without the person manually choosing that exact source.
Copilot creates a new document containing the instruction The output becomes a carrier. It can remain dormant during ordinary sharing.
Someone later reuses that output with Copilot The copied instruction may activate again and affect another generation or edit.
Microsoft Copilot for Word test showing a propagated instruction selected near the bottom of a generated report.
The researcher’s Word test shows the propagated instruction selected near the bottom of a Copilot-generated report. The prompt text is intentionally blurred. Source: Håkon Måløy.

Why this is not a normal Word virus

A traditional malicious document usually relies on executable content, a software vulnerability, or a social-engineering step that launches code. This proof of concept relies on language being interpreted by an AI assistant. It changes the meaning or contents of documents through an authorized feature rather than installing a payload on Windows.

That distinction changes the response. Antivirus scanning remains important for macros, exploits, and embedded malware, but a clean malware result does not prove that every sentence supplied to an AI assistant is trustworthy. Conversely, finding hidden text does not prove that a file compromised Copilot; templates, accessibility work, redactions, and formatting mistakes can also leave non-obvious content.

The same visibility gap appeared in research on hidden instructions targeting the Kiro coding assistant. The execution paths differ, but both cases show why an AI-generated output must be reviewed as a new artifact rather than accepted as a neutral copy of its sources.

How to check a document before using it with Copilot

  1. Keep unverified files out of the AI context. Do not attach an external document to Copilot until you know who supplied it and why. In a business tenant, ask the Microsoft 365 administrator how Work IQ source selection is governed for sensitive tasks.
  2. Inspect a copy, not the only original. In desktop Word for Windows, use File → Info → Check for Issues → Inspect Document. Document Inspector can flag text formatted with the Hidden font effect.
  3. Check what the inspector cannot see. Microsoft says Document Inspector does not detect every concealment method, including white text on a white background. On a copy, select all text and set the font color to Automatic, or export the text to a plain-text format for review. Preserve the original for comparison.
  4. Review the output as a change set. Compare names, dates, totals, conclusions, and links against the source. Use Track Changes, version history, or a document comparison instead of checking only whether the prose sounds plausible.
  5. Limit automatic reuse. Store approved source material separately from incoming files, and avoid broad prompts that let the assistant select an uncontrolled set of documents for high-impact reports.

Do not treat this process as a substitute for normal malicious-document controls. A Word file can still exploit a vulnerability or carry dangerous active content. The separate Microsoft Word Preview Pane vulnerability analysis explains why patching and protected viewing remain necessary even when Copilot is not involved.

What to do if a suspicious file was already used

  1. Pause sharing of the source document and every Copilot-generated file derived from it.
  2. Preserve versions and record which prompt, source files, user, and time produced each output.
  3. Compare the output with trusted records, paying special attention to financial figures, names, decisions, deadlines, and instructions.
  4. Restore a known-good version rather than deleting only the visible suspicious line.
  5. Notify the Microsoft 365 administrator so they can review shared locations, version history, audit records, and other documents that reused the output.
  6. If the file came from outside the organization, retain the sender and delivery context for the security team. Scan it for conventional threats as a separate check.

What the finding does not prove

  • There is no public evidence in the report of active exploitation against real organizations.
  • The proof of concept does not install malware or execute a traditional Word virus.
  • Simply opening or sharing the document was not shown to activate the instruction.
  • Microsoft’s mitigations raised the bar for the original payloads, although the researcher said the broader class remained reproducible.

The practical lesson is therefore measured: treat third-party documents as untrusted input before Copilot sees them, and validate AI-produced documents before they become sources for the next task. That breaks the demonstrated propagation path without turning every hidden formatting artifact into an incident.

References

  1. Håkon Måløy. “Context Collapse, Part 3: AI Worming Through Word.” Published July 28 and updated July 30, 2026. Primary research report.
  2. Microsoft Support. “Edit with Copilot in Word.” Accessed July 30, 2026. Copilot for Word feature documentation.
  3. Microsoft Support. “Remove hidden data and personal information by inspecting documents, presentations, or workbooks.” Accessed July 30, 2026. Document Inspector guidance and limitations.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?