Microsoft: SesameOp malware abuses OpenAI Assistants API in attacks
ID: 29138d7f-d9c0-5e87-a01d-26164788d915
STIX ID: report--29138d7f-d9c0-5e87-a01d-26164788d915
Feed Name: Bleeping Computer
Microsoft DART identified SesameOp, a .NET backdoor used in a July 2025 cyberattack that leverages the OpenAI Assistants API as a covert storage/relay C2 channel to fetch compressed, encrypted commands and exfiltrate encrypted data; it was deployed via a heavily obfuscated loader and AppDomainManager injection into Visual Studio utilities, achieved months-long persistence through internal web shells and malicious processes, and prompted Microsoft and OpenAI to disable the abused account and API key while recommending detection and hardening mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
