OpenAIAgent.Netapi64 is a malware family tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity November 4, 2025.
OpenAIAgent.Netapi64 is a Windows-based, .NET‑driven malware family (Netapi64) that leverages OpenAI services to establish covert command-and-control and to store or retrieve malware instructions and data. Its use of OpenAI APIs and accounts as a backchannel makes communications harder to detect and highlights a growing trend of abusing AI cloud platforms for backdoors.
In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised…
Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to…