A document-based, self-replicating AI worm targeting Microsoft Word's Copilot has been demonstrated for the first time.

Microsoft has integrated its Copilot AI generator assistant into its office suite, which includes office software such as Word and Excel. Now, security researcher Haakon Morley has demonstrated for the first time the effectiveness of a document-based self-replicating malware called an 'AI worm' that targets Copilot for Word.
Context Collapse, Part 3 - AI Worming through Word | En Klype Salt
Word worm crawls into Copilot, spreads chaos
https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588
Microsoft is focusing on its generative AI assistant, Copilot, and in April 2026, it officially implemented an agent function that allows users to directly manipulate Word, Excel, and PowerPoint. This enables users to perform advanced office-related tasks using Copilot.
Microsoft officially releases Copilot agent functionality for Word, Excel, and PowerPoint - GIGAZINE

However, on July 28, 2026, Morley announced that he had successfully demonstrated a proof of concept for an 'AI worm that can tamper with documents created and edited in Word, self-replicate, and spread to new documents.' To the best of Morley's knowledge, this is the first public demonstration of an AI worm self-replicating via documents through the normal workflow of a mainstream commercial productivity suite.
The AI worm attack workflow demonstrated by Mr. Morley is as follows:
1: The attacker inserts hidden instructions (AI worm) into a document that will later be used with Copilot for Word.
2: When a user loads a document into Copilot, Copilot interprets the hidden instructions as the user's request and alters the document being created or edited according to the instructions.
3: Copilot copies instructions hidden in the original document into the new document without them being detected.
4. When a document created or edited by Copilot is used in another Copilot-assisted workflow, the instructions spread to yet another document.
As described above, the AI worm can continue to self-replicate beyond the attacker's control, potentially making it difficult to even identify the source of the infection by the time it's discovered. Morley states, 'This attack can continue without the involvement of a compromised website or the original malicious document. The attacker doesn't need access to the victim's Microsoft 365 tenant; all they need to do is share the malicious document with the victim.'
The AI worm's prompts consisted of two parts: 'instructions on how to affect the document,' such as altering the meaning of a summary or falsifying numbers, and 'instructions for the AI worm to self-replicate.' In Morley's proof of concept, the prompts were written in white text on a white background, so that users could not detect the problem by visually checking the original document.
The blurred area at the bottom of the screenshot below is the prompt from the AI worm created by Mr. Morley. Note that the background and text colors have been changed in this screenshot to make the prompt easier to read, but in reality, it is written in white text on a white background and is unreadable. The AI worm self-replicates by secretly copying similar prompts to new documents.

Morley notified Microsoft of the proof-of-concept AI worm on March 6, 2026, and has since been working with Microsoft to find mitigation measures. Microsoft deployed several patches to improve security levels, but Morley was able to bypass them by modifying the prompts.
The AI worm was initially delayed twice because Microsoft was unable to find an effective mitigation measure. However, after the agreed-upon 144-day adjustment period had passed, Morley decided to go ahead with the disclosure, stating that 'there is currently no definitive solution to this widespread class of vulnerabilities.'
For AI tools to be useful, they need to process data such as emails, documents, and web pages, but this data could be controlled by attackers. Furthermore, even when AI tools attempt to determine whether the source data contains malicious content, it's impossible to completely rule out the possibility that the attacker's instructions could influence that determination.
Morley stated, 'Systems that integrate today's large-scale language models into trusted workflows must assume that a certain percentage of breaches will occur when attacker-controlled content enters the model's context.'

While there is currently no complete solution for customers, Mr. Morley recommends that they 'treat all documents obtained from external sources as untrustworthy when using Copilot,' 'fully check the content and security of documents before entering them into Copilot,' and 'fully check the content of documents created or edited with Copilot before sending them.' Since AI worms self-replicate, 'documents obtained from external sources' here includes all documents created within the company and data sent from trusted sources.
In response to this advice, the overseas media outlet The Register commented, 'If you actually have to read the contents of the document, you'd be better off removing Copilot from the process and thinking for yourself.'
Related Posts:
in AI, Web Service, Security, Posted by log1h_ik







