English

SecurityMicrosoft CopilotHåkon Mordroy

AI Worm Threat Reported: Instructions Self-Propagating via Microsoft Copilot

This article is a translation. Read the Japanese original

Håkon Morøy, a data scientist from Norway, has reported a phenomenon where Microsoft Copilot misinterprets text strings within a Word document as commands when reading the file.

This technique is known as "cross-domain prompt injection."

Attackers embed malicious instructions within a document, often using white text to make them nearly invisible to human readers.

According to the report, when Copilot reads such a document, it not only rewrites the content according to the instructions but also copies the same commands into any newly generated documents.

As a result, malicious instructions could be passed from one internal document to another, potentially exhibiting the behavior of a self-propagating "AI worm."

According to Morøy, Microsoft received reports of the issue in March 2026 and has since implemented countermeasures, including mitigation strategies and model updates.

However, it has been confirmed that the attack can function again by simply altering the phrasing of the commands.

Microsoft has explained that it has strengthened its defenses through a layered security approach, but it is said that completely preventing such attacks is difficult.

Morøy recommends verifying the contents of documents obtained from external sources before allowing the AI to read them, and checking AI-generated outputs before utilizing or sharing them.


Source: 「Copilot、Word文書まとめて」で社内全滅? 勝手に増殖するAIウイルスで大騒ぎ:895th Lap (ITmedia AI+, 2026-09-04)