SesameOp Backdoor Exploits OpenAI API for Cyber Espionage

SesameOp Backdoor Exploits OpenAI API for Cyber Espionage

First seen 23 Nov 2025, 03:35 UTC ThehackernewsCybernewsCsoonlineTheregisterOpentools.Ai+5 76% similarity 35.1

Article Content

Browse articles
ThreatCluster

In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised devices while blending its communications with legitimate AI traffic, complicating detection efforts. The backdoor was part of a months-long cyber-espionage campaign that went undetected until its discovery by Microsoft's Detection and Response Team.

ThreatCluster AI

Community

Browse all →