SesameOp Backdoor Detection: Microsoft Discovers New Malware Abusing OpenAI Assistants API in Cyber-Attacks
ID: ed36b3d4-fe8d-5a21-8942-a1f81add617d
STIX ID: report--ed36b3d4-fe8d-5a21-8942-a1f81add617d
Feed Name: SOC Prime Blog
Microsoft DART identified a novel backdoor named SesameOp that uses the OpenAI Assistants API as a covert command-and-control channel to retrieve compressed, encrypted commands and return execution results; the campaign involved a .NET loader (Netapi64.dll) and a backdoor (OpenAIAgent.Netapi64) persisted via AppDomainManager injection into compromised Visual Studio utilities, was heavily obfuscated, and maintained long-term access for months — Microsoft shared findings with OpenAI and recommended detection, endpoint protections, and network auditing as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
