Skip to content

AI Worm Leverages Microsoft Copilot as Propagation Mechanism in Office Documents

Bottom line: A self-replicating worm exploits Microsoft Copilot to spread through Office documents while bypassing standard security controls such as DLP and email filtering, with the underlying vulnerability still unpatched.

Norwegian AI researcher Håkon Måløy has documented a self-replicating malware pattern that spreads via Microsoft Copilot and other Office applications. Microsoft has confirmed the findings and implemented partial mitigations without addressing the underlying vulnerability.

The attack operates on a simple principle: an attacker embeds instructions in a document that later serves as an input source for Copilot-powered workflows – for example, when generating or editing Word documents such as financial reports. The embedded instructions can manipulate numbers or content in the newly created document. Critically, the self-replicating mechanism functions as follows: the worm copies itself into the new document, which then serves as an infection source again during the next Copilot-powered task. Håkon Måløy describes this as one of the first public demonstrations of a document-based AI worm with self-propagation through normal workflows in a widely used commercial productivity suite.

For CISOs, this threat is considerably more severe than superficial examination suggests. According to Aman Mahapatra, Chief Strategy Officer at technology consultant Tribeca Softtech, the malware pattern bypasses all classical enterprise security measures: email security controls are ineffective because the document is not malicious upon receipt; Data Loss Prevention (DLP) systems are useless because data exfiltration occurs via the authenticated Copilot session of the user; endpoint protection fails because no code execution occurs, only instructions are followed by an AI service authorized by the enterprise. The malware pattern thus leverages legitimate enterprise-wide collaboration and AI workflows as a distribution channel.

Microsoft has been collaborating with the Microsoft Security Response Center (MSRC) since 3 March. The company has implemented and distributed several limited mitigations that make the attack vector less reliable and limit its reach – without, however, addressing the underlying vulnerability. Måløy chose to disclose the issue because in his view, defensive measures may be impossible if organisations do not know the risk category. Researchers have been warning of this type of attack for two years already.

Microsoft stated that it employs a defense-in-depth strategy with protective measures at multiple points and continuously strengthens them. The company recommends customers install the latest updates, utilise multi-layered security measures, treat content from unknown sources with caution, and review AI-generated content before use or sharing. According to Måløy, distinguishing between data and instructions in language models is non-trivial and may be only a partial aspect of the solution.


Source: www.csoonline.com · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: