OpenAIAgent.Netapi64 Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 4, 2025
Last Seen
November 4, 2025

OpenAIAgent.Netapi64 is a malware family tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity November 4, 2025.

Overview

OpenAIAgent.Netapi64 is a Windows-based, .NET‑driven malware family (Netapi64) that leverages OpenAI services to establish covert command-and-control and to store or retrieve malware instructions and data. Its use of OpenAI APIs and accounts as a backchannel makes communications harder to detect and highlights a growing trend of abusing AI cloud platforms for backdoors.

Related Threat Clusters

  • SesameOp Backdoor Exploits OpenAI API for Cyber Espionage

    In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised…

    11 articles · Updated November 6, 2025
  • SesameOp Backdoor Exploits OpenAI API for Covert Cyber Operations

    Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to…

    14 articles · Updated November 6, 2025

Recent Intelligence Reports

  • SesameOp Backdoor Uses OpenAI API for Covert C2 — Darkreading · November 4, 2025
  • Hackers caught hiding malware instructions and data in OpenAI accounts — Cybernews · November 4, 2025

CVSS v3.1 Breakdown