logo

SesameOp Backdoor Detection: Microsoft Discovers New Malware Abusing OpenAI Assistants API in Cyber-Attacks

ID: ed36b3d4-fe8d-5a21-8942-a1f81add617d

STIX ID: report--ed36b3d4-fe8d-5a21-8942-a1f81add617d

Feed Name: SOC Prime Blog

Threat Score
75/100

Date Published: 2025-11-04

Date Updated: 2026-04-30

Author: Veronika Telychko

...
...

Microsoft DART identified a novel backdoor named SesameOp that uses the OpenAI Assistants API as a covert command-and-control channel to retrieve compressed, encrypted commands and return execution results; the campaign involved a .NET loader (Netapi64.dll) and a backdoor (OpenAIAgent.Netapi64) persisted via AppDomainManager injection into compromised Visual Studio utilities, was heavily obfuscated, and maintained long-term access for months — Microsoft shared findings with OpenAI and recommended detection, endpoint protections, and network auditing as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.