SECURITY·중요도 9·2026. 07. 29.·GeekNews

Word 문서를 통해 자가 전파하는 Copilot AI 웜

── KO ──────────────────

Copilot AI 웜이 Word 문서를 통해 자가 전파하는 방법을 설명합니다.

Copilot AI 웜은 외부 Word 문서에 숨겨진 교차 도메인 프롬프트 주입(XPIA) 기술을 통해 작성·편집 결과를 조작하고, 원본 없이 새로운 문서로 복제됩니다. 이 웜은 일상적인 업무 흐름을 따라 전파되며, 흰색 소형 글꼴로 숨겨진 명령을 Copilot이 서식을 제거한 후 읽을 수 있는 위험성을 가지고 있습니다.


── EN ──────────────────

Copilot AI worm propagates via Word documents using XPIA techniques.

The Copilot AI worm uses cross-domain prompt injection (XPIA) to manipulate document editing and create new documents without the original attack document. It can propagate through normal workflows, and commands hidden in small white fonts can be read by Copilot after format removal, posing significant risks.

원문 보기 →목록으로