ATRIUMsearch → argument graph
Article · 2026-07-29 · 5 moments

AI Worming through Word

AI Worming through Word Neat new prompt injection variant by Håkon Måløy, who found a way to upgrade prompt injection attacks against Microsoft Word to full self-replicating worms: An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting ✦ AI generated

01
Mechanism

A carrier document, when used in subsequent Copilot-assisted workflows, triggers the hidden instructions again and propagates them into further documents even without the attacker's original document being present.

Once infected, a document becomes a carrier that propagates the hidden instructions through any future Copilot workflow that uses it, removing dependence on the original attacker document.

transcript

Article author: If the carrier is subsequently used in another Copilot-assisted workflow, the instructions can trigger again and propagate into further documents, even without the attacker's original document being present.

provides context · 2

02
Mechanism

An attacker places hidden instructions in a source document that Copilot for Word interprets as part of the user's request, causing it to manipulate the document being edited and copy the instructions into the output, turning that output into a new carrier document.

The attack works by embedding hidden instructions in a source document that Copilot treats as user requests, manipulating the document being drafted and copying the instructions into the resulting output.

transcript

Article author: An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user's request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier.

extends · 1provides context · 2

03
Claim

Håkon Måløy discovered a prompt injection variant against Microsoft Word that achieves full self-replicating worm behavior.

Security researcher Håkon Måløy found a prompt injection technique against Microsoft Word's Copilot that can self-replicate like a worm.

transcript

Article author: Neat new prompt injection variant by Håkon Måløy, who found a way to upgrade prompt injection attacks against Microsoft Word to full self-replicating worms

explains mechanism · 2gives example · 1provides context · 2

04
Fact

The vulnerability was responsibly disclosed to Microsoft 144 days ago with no mitigation that covers the full class of attack produced so far.

Håkon Måløy responsibly disclosed the vulnerability to Microsoft, who had 144 days to develop a fix, but no comprehensive mitigation for this class of attack exists yet.

transcript

Article author: It was responsibly disclosed to Microsoft who then had 144 days to work on a fix, but so far (unsurprisingly) there's no mitigation that covers the full class of attack.

gives example · 1provides context · 1

05
Context

While hidden white-on-white text is a known technique, this attack is the first to deliberately copy instructions into outputs to achieve self-replication.

Hidden text techniques are widely used, but this variant is genuinely novel because it deliberately copies its own instructions into every output to self-replicate.

transcript

Article author: We've seen plenty of hidden white-on-white text before - the kids are using it in their job applications now - but this is the first one I've seen that deliberately copies instructions to self-replicate itself.

gives example · 1

Highlight slides
Related episodes