AppDomainManager injection - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 4, 2025
Last Seen
February 2, 2026

AppDomainManager injection is a mitre_attack tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity February 2, 2026.

Related Threat Clusters

  • SesameOp Backdoor Exploits OpenAI API for Cyber Espionage

    In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised…

    11 articles · Updated November 6, 2025
  • RedKitten Campaign Targets Iranian Protest Monitors with AI Malware

    The RedKitten campaign has emerged, utilizing AI-driven malware to target individuals and organizations monitoring human rights violations during the Dey 1404 protests in Iran. Discovered by HarfangLab, the campaign…

    4 articles · Updated February 2, 2026
  • SesameOp Backdoor Exploits OpenAI API for Covert Cyber Operations

    Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to…

    14 articles · Updated November 6, 2025

Recent Intelligence Reports

  • RedKitten Campaign Uses AI Malware to Target Iranian Protests — Technadu · February 2, 2026
  • OpenAI Assistants API Exploited in 'SesameOp' Backdoor — Infosecurity-Magazine · November 4, 2025
  • SesameOp Backdoor Uses OpenAI API for Covert C2 — Darkreading · November 4, 2025

CVSS v3.1 Breakdown