Security researchers have identified a novel backdoor, dubbed SesameOp, which leverages the OpenAI Assistants API to establish covert command and control (C2) channels and facilitate espionage activities. The malware abuses the legitimate API to blend malicious traffic with normal AI assistant usage, making detection by traditional security tools more challenging. Both independent security researchers and Microsoft Incident Response have confirmed that SesameOp uses this technique to exfiltrate data and receive attacker instructions, highlighting a new trend in the abuse of generative AI platforms for cyber operations.
The use of the OpenAI Assistants API for C2 communications allows threat actors to bypass many conventional network defenses, as traffic to popular AI services is often considered benign. Security teams are advised to monitor for unusual patterns of API usage and to review access logs for signs of unauthorized or suspicious activity involving AI platforms. The discovery of SesameOp underscores the need for organizations to update their threat models to account for the potential misuse of generative AI services in advanced malware campaigns.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft published technical details on SesameOp, including its loader and .NET backdoor components, and released mitigations, Microsoft Defender detections, and a hunting query to identify connections to api.openai.com. Microsoft also stated the issue was abuse of legitimate API functionality rather than a vulnerability in OpenAI.
During a sophisticated intrusion in 2025, the actor maintained access to the victim environment for months, using internal web shells and compromised Microsoft Visual Studio utilities with .NET AppDomainManager injection for persistence and defense evasion.
As part of the joint investigation, OpenAI disabled an API key and associated account believed to have been used by the threat actor for SesameOp command-and-control operations.
After the backdoor was identified, Microsoft and OpenAI jointly investigated the actor's misuse of the OpenAI Assistants API for C2 activity. Their review found limited API calls and no evidence of broader abuse of OpenAI models or services.
In July 2025, Microsoft Incident Response (DART) identified a previously unknown backdoor dubbed SesameOp while responding to the intrusion. The malware used the OpenAI Assistants API as a covert command-and-control channel to receive commands and return execution results.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
10 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesocradar.io
Open sourcego.theregister.com
Open sourcecsoonline.com
Open sourcedarkreading.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.