Microsoft security researchers have identified a new backdoor malware, named SesameOp, which leverages the OpenAI Assistants API as a covert command-and-control (C2) channel. The malware was discovered during an investigation into a July 2025 cyberattack, where attackers maintained persistent access to compromised environments by using legitimate cloud services for C2 communications, rather than traditional malicious infrastructure. This approach allowed the threat actors to evade detection and maintain long-term espionage operations within the targeted networks.
The SesameOp backdoor operates by using the OpenAI Assistants API to fetch compressed and encrypted commands, which are then decrypted and executed on infected systems. Information harvested from the compromised environment is also encrypted and transmitted back through the same API channel. The attack chain involved a heavily obfuscated loader and a .NET-based backdoor, deployed via .NET AppDomainManager injection into multiple Microsoft Visual Studio utilities, with persistence established through internal web shells and strategically placed malicious processes. Microsoft clarified that the attack does not exploit a vulnerability in OpenAI's platform, but rather abuses its legitimate features for malicious purposes.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed that the SesameOp malware was using the OpenAI Assistants API as part of its attacks. No earlier or additional distinct real-world events are provided in the reference content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.