Bleepingcomputer
SesameOp Backdoor Exploits OpenAI API for Covert Cyber Operations
First seen 2 Dec 2025, 18:33 UTC
•



+8
•83% similarity
•24.4
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to maintain persistent access to compromised environments and manage devices covertly, marking a significant shift in cyber-espionage tactics by repurposing legitimate AI infrastructure. The backdoor was identified during an investigation into a cyberattack that began in July 2025.
ThreatCluster AI