
Fake SSMS on GitHub Spreads Crypto-Stealing OkoBot
Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…
A security researcher demonstrated that Microsoft Copilot for Word can be tricked by hidden text inside a Word document, causing Copilot to follow attacker instructions. The result is a self-propagating “AI worm” that silently modifies documents and embeds the same hidden prompt into new files, spreading through normal document sharing without traditional malware.
A security researcher demonstrated that Microsoft Copilot for Word can be manipulated through hidden text embedded inside a Word document. The technique involves formatting a JSON-style prompt as white text on a white background, so it is invisible to anyone reading the document normally. When a user opens the file and asks Copilot to draft or edit content based on it, Copilot strips away formatting, reads the hidden text, and treats those embedded instructions as part of the legitimate user request.
The most notable part of this attack is what happens next. Copilot does not just follow the hidden instructions once. It appends the full malicious prompt back into the newly created or edited document as hidden text. That new file then becomes a carrier itself. If it is shared with a colleague, partner, or client who also uses Copilot for Word, the cycle repeats without any traditional malware, macros, or attachments involved.
This is not a phishing email with obvious red flags or a malicious executable that antivirus tools can catch. The payload is plain text hidden through simple formatting tricks, and the propagation happens through completely normal, expected behavior: opening a shared document and asking an AI assistant to help edit it. The researcher reports that the worm chain continued to function even after mitigations and newer model versions were introduced, pointing to a broader architectural weakness in how these AI assistants process untrusted document content rather than a single fixable bug.
Organizations across legal, finance, HR, executive, and general Microsoft 365 user populations should treat externally sourced documents as untrusted before feeding them into Copilot or similar AI assistants. Manual review of attachments before using them as Copilot source material, along with careful verification of Copilot-generated output before it is shared or reused, helps break the propagation chain. For teams that do not rely heavily on Copilot for Word, disabling it entirely (through File, Options, Copilot, and clearing the Enable Copilot checkbox) removes the exposure altogether. Because there is currently no complete mitigation for this class of prompt-injection attack, awareness and cautious document handling remain the most practical defenses available today.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers hide a JSON-formatted prompt as white text on a white background inside a Word document. When a user asks Copilot to draft or edit based on that document, Copilot reads the hidden instructions and appends the same hidden prompt into the new output file, turning it into a carrier that spreads through normal document sharing.
According to the researcher, the worm chain still worked after Microsoft mitigations and newer model upgrades, suggesting the weakness is architectural rather than a single patchable bug.
Yes, disabling Copilot in Word is one way to reduce exposure. In Word, users can go to File, Options, Copilot, clear the Enable Copilot checkbox, and restart Word.
Treat documents from outside the organization as untrusted, review them manually before using them as Copilot source material, and carefully verify any Copilot-edited output before sharing or reusing it.
Imagine a Word document that quietly reprograms Copilot… and then spreads itself every time you share it. A researcher showed this: attackers hide a JSON prompt as white text on white background in a Word file. When you ask Copilot for Word to draft or edit based on that doc, Copilot strips the formatting, reads the hidden instructions, and quietly rewrites your document. Here’s the nasty part: Copilot can then append that same malicious JSON prompt back into the file as hidden white text. The new document you save and email on becomes a fresh carrier, and the worm chain keeps working even after model updates. Your move: if a document comes from outside the company, read it first, then only use Copilot on it after you’ve reviewed the content, and double-check Copilot’s edits before you hit send.

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…

Scammers quickly set up fake piracy pages for Christopher Nolan’s “The Odyssey” to trick people into either clicking a fake browser “Fix It Now” warning or…

North Korea–linked actors used fake developer job offers inside a Slack community to trick targets into running a “coding assessment” project. The repository…