Untrusted Documents: The Underlying Issues
Be cautious of untrusted documents, everyone. Research indicates that an attacker can embed harmful instructions within a Word document, and when you integrate that with Copilot for Word, it could disrupt the document’s output and propagate those malicious instructions into new files without your awareness.
The Mind Behind the Revelation
Håkon Måløy, a Norwegian data scientist holding a PhD in applied AI and ML, disclosed this in a blog entry. He provided extensive information but prudently kept the specific prompt payload confidential since a reliable solution has not yet been established. Curiously, this marks the first occurrence of an AI-worm autonomously propagating through regular workflows in a popular suite.
Microsoft’s Misstep
The Battle with the Worm
Måløy has collaborated with Microsoft since March 2026 to combat this worm, but the clever little critter continues to evade capture. Microsoft attempted to eliminate it with updates, but the worm adeptly evades detection through rephrasing, even manipulating financial data in subtle ways. They postponed announcing the issue for quite some time, but after 144 days, Måløy felt it was crucial to share the information.
Microsoft’s Efforts to Mitigate
“The coordination phase with Microsoft has concluded, and we still lack a genuine solution,” Måløy mentioned. “Two mitigation strategies didn’t secure a resolution.”
How The Cunning Worm Operates
The Infected Document Shuffle
Måløy elucidated how the worm infiltrates Word documents. Imagine you’re preparing a financial report and download a market analysis from a supposedly reliable source. Voilà! The document contains concealed malicious instructions, buried in small white text. Copilot unknowingly adheres to these hidden commands, modifying figures and replicating the worm. If another unsuspecting individual utilizes your infected report, the worm continues to spread, making it a proper challenge to trace back.
The Ongoing Propagation
“The attack persists without needing the original malicious document or compromised site,” Måløy stated. All the attacker requires is to distribute a contaminated document to someone.
The Fundamental Flaw
Cross-Domain Prompt Injection Attack
Måløy asserts that he has identified a new variant of cross-domain prompt injection attack. AI assistants must manage various data types that an attacker could manipulate, and if an LLM fails to detect an attack without examination, the harm may already be inflicted.
Endless LLMs?
Introduce another model to scan for threats? You’re merely relocating the problem. Måløy describes this as a “LLMs all the way down” situation. We need systems with objectives that don’t depend on processed data, but until then, attackers might still find a subtle way in.
What Actions Can You Take?
Vigilance is Crucial
Well, aside from telling Copilot to go away, not much can be done. There’s no foolproof solution from the user end at the moment, according to Måløy. Treat external documents as unreliable, examine everything before integrating it into Copilot, and verify all output that Copilot generates. You might as well do it yourself, right?
Microsoft’s Perspective
Microsoft acknowledged the research but didn’t alleviate concerns significantly. Their defense-in-depth strategy aims to thwart those troublesome instructions and maintain task alignment. They recommend keeping software updated, utilizing multiple security layers, and reviewing AI-generated outputs.
Attempted to reach Måløy for a conversation, but he has been unreachable before we went to publication.
Microsoft’s Word Challenges: The Ongoing Saga