SesameOp campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 6, 2025
Last Seen
November 6, 2025

SesameOp campaign is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 6, 2025; most recent activity November 6, 2025.

Overview

SesameOp is a backdoor campaign described as exploiting the OpenAI API to establish covert command-and-control and data exfiltration channels. It leverages legitimate API traffic to blend in with normal activity, underscoring the risk of AI platform abuse in cybersecurity and the need for robust abuse controls and monitoring.

Related Threat Clusters

  • SesameOp Backdoor Exploits OpenAI API for Cyber Espionage

    In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised…

    11 articles · Updated November 6, 2025
  • SesameOp Backdoor Exploits OpenAI API for Covert Cyber Operations

    Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to…

    14 articles · Updated November 6, 2025

Recent Intelligence Reports

  • SesameOp Backdoor Explained: What You Need to Know About the OpenAI API Exploitation — Socradar · November 6, 2025

CVSS v3.1 Breakdown