SesameOp Backdoor Exploits OpenAI API for Covert Cyber Operations

SesameOp Backdoor Exploits OpenAI API for Covert Cyber Operations

First seen 2 Dec 2025, 18:33 UTC Blogs.MicrosoftBleepingcomputerThehackernewsCybernewsCsoonline+8 83% similarity 24.4

Article Content

Browse articles
ThreatCluster

Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to maintain persistent access to compromised environments and manage devices covertly, marking a significant shift in cyber-espionage tactics by repurposing legitimate AI infrastructure. The backdoor was identified during an investigation into a cyberattack that began in July 2025.

ThreatCluster AI

Community

Browse all →