SesameOp campaign is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 6, 2025; most recent activity November 6, 2025.
SesameOp is a backdoor campaign described as exploiting the OpenAI API to establish covert command-and-control and data exfiltration channels. It leverages legitimate API traffic to blend in with normal activity, underscoring the risk of AI platform abuse in cybersecurity and the need for robust abuse controls and monitoring.
In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised…
Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to…