Sesameop is a malware family tracked across 9 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity November 9, 2025.
SonicWall reported a security incident involving unauthorized access to backup firewall configuration files stored in a cloud environment. The company attributed the breach to a state-backed threat actor and engaged…
Microsoft researchers discovered the SesameOp backdoor, which utilizes OpenAI’s Assistants API for remote access and data theft. The malware employs the API to store and relay commands from its command and control (C&C)…
Microsoft's Detection and Response Team (DART) identified a new backdoor malware named SesameOp that utilizes the OpenAI Assistants API for command-and-control communications. This malware allows attackers to maintain…
In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised…
SonicWall reported unauthorized access to backup firewall configuration files in September 2025, attributed to a state-backed threat actor. The company engaged Mandiant for an investigation and communicated with…
Recent malware developments include the SesameOp backdoor utilizing OpenAI Assistants API for command and control, and advanced SSH-Tor backdoors targeting the defense sector. Additionally, Gootloader has resurfaced…
Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to…
Microsoft researchers identified the SesameOp backdoor, which utilizes OpenAI’s Assistants API for remote access and data theft. This malware component is designed to store and relay commands from a command and control…
Recent malware campaigns have been identified utilizing innovative techniques for delivery and execution. Notable threats include the use of JSON storage services for malware delivery and the resurgence of Gootloader,…