SesameOp Malware Exploits OpenAI API for Covert Command-and-Control Operations

SesameOp Malware Exploits OpenAI API for Covert Command-and-Control Operations

First seen 4 Nov 2025, 11:09 UTC Blogs.MicrosoftBleepingcomputer 83% similarity 35.1

Article Content

Browse articles
ThreatCluster

Microsoft's Detection and Response Team (DART) identified a new backdoor malware named SesameOp that utilizes the OpenAI Assistants API for command-and-control communications. This malware allows attackers to maintain persistent access to compromised environments and remotely manage infected devices. The discovery was made during an investigation into a cyberattack that occurred in July 2025.

ThreatCluster AI

Community

Browse all →