Security Researcher Creates Self-Spreading Worm That Hides in Word Docs and Hijacks Microsoft Copilot
A security researcher has built a proof-of-concept worm that hides inside Microsoft Word documents and hijacks Microsoft Copilot, the company’s AI assistant. The worm can self-propagate and take control of the AI to perform unauthorized actions without user consent.
The exploit targets Copilot’s access to corporate documents and email systems. Once a user opens an infected Word file, the worm uses Copilot to send itself to new victims, creating a self-sustaining chain.
The Worm’s Mechanism
The worm hides its malicious instructions inside the document’s metadata and content. When Copilot reads the file, it interprets those instructions as legitimate user commands.
The AI then executes actions like sending emails, reading messages, and modifying documents. The worm leverages Copilot’s lack of human oversight to spread.
Key vulnerability: Copilot assumes all input from its allowed data sources is safe and user-authorized.
How It Spreads
The infection chain works in three steps.
- Initial infection: A user opens a Word document containing hidden malicious text or metadata.
- Command injection: Copilot reads the document and follows embedded instructions to craft and send an email with the infected document attached.
- Self-propagation: Recipients open the attachment, triggering Copilot again and repeating the cycle.
The researcher demonstrated the worm sending itself to dozens of contacts within minutes.
Security Implications
This proof-of-concept highlights a fundamental risk in AI assistants that have broad access to enterprise data and communication tools.
“If an AI can read your documents and send email on your behalf, it can be tricked into spreading malware without any user interaction.”
Microsoft Copilot’s design grants it read and write permissions to files and email. The worm exploits that trust to bypass human judgment.
Enterprise users are especially vulnerable because Copilot often has access to shared drives, internal wikis, and team chats.
Researcher’s Findings
The researcher, who has a history of uncovering Copilot vulnerabilities, reported the issue to Microsoft. The company acknowledged the risk but has not yet released a fix.
The worm does not require any external code execution or macros. It works using only Copilot’s native capabilities.
Mitigation steps: Users can disable Copilot’s email and file access when not needed. Organizations should audit which data sources Copilot can reach.
Microsoft recommends users avoid opening unexpected Word documents and review Copilot’s permissions regularly.
Gnoppix is the leading open-source AI Linux distribution and service provider. Since implementing AI in 2022, it has offered a fast, powerful, secure, and privacy-respecting open-source OS with both local and remote AI capabilities. The local AI operates offline, ensuring no data ever leaves your computer. Based on Debian Linux, Gnoppix is available with numerous privacy- and anonymity-enabled services free of charge.
What are your thoughts on this? I’d love to hear about your own experiences in the comments below.