Microsoft Uncovers SesameOp Backdoor Exploiting OpenAI's API for Covert Espionage Operations

Reviewed byNidhi Govil

3 Sources

Share

Microsoft's cybersecurity team discovered a sophisticated backdoor called SesameOp that abuses OpenAI's Assistants API as a command-and-control channel. The malware hides malicious activities by blending with legitimate AI traffic, enabling long-term espionage operations while evading traditional detection methods.

Discovery and Initial Detection

Microsoft's Detection and Response Team (DART) has uncovered a sophisticated backdoor operation that represents a concerning evolution in cybercriminal tactics. The malware, dubbed SesameOp, was first detected in July 2025 during an investigation into what Microsoft described as a "sophisticated security incident" where unknown threat actors had maintained persistence within a target environment for several months

1

2

.

Source: Mashable

Source: Mashable

What makes SesameOp particularly noteworthy is its innovative approach to command-and-control communications. Rather than establishing traditional malicious infrastructure that security teams typically monitor, the backdoor exploits OpenAI's Assistants API as a covert communication channel

3

.

Technical Architecture and Operation

The SesameOp backdoor operates through a sophisticated multi-component system designed for maximum stealth and persistence. The malware consists of a loader component called "Netapi64.dll" and a .NET-based backdoor named "OpenAIAgent.Netapi64" that leverages the OpenAI API for command-and-control operations

2

.

Source: The Register

Source: The Register

The attack chain begins with a technique known as ".NET AppDomainManager injection," which allows the malware to plant itself within legitimate processes. The DLL component is heavily obfuscated using Eazfuscator.NET and is loaded at runtime through this injection method, making detection significantly more challenging

1

.

Once operational, the backdoor fetches encrypted commands from OpenAI's Assistants API, decrypts and executes them locally, then posts the results back through the same channel. This creates what Microsoft describes as a "complex arrangement" of internal web shells designed to execute commands relayed from persistent, strategically placed malicious processes

2

.

Stealth and Evasion Techniques

The genius of SesameOp lies in its ability to hide in plain sight. By piggy-backing on OpenAI's legitimate cloud infrastructure, the malware avoids traditional detection methods that look for suspicious domains, questionable IP addresses, or obvious command-and-control infrastructure. Network traffic to "api.openai.com" appears entirely normal to security monitoring systems

1

.

Microsoft's analysis reveals that the implant uses payload compression and layered encryption to further obscure commands and exfiltrated data. The malware doesn't interact with ChatGPT or perform any conversational AI functions; instead, it simply hijacks OpenAI's infrastructure as a data courier, blending malicious communications with the millions of legitimate API calls made daily

1

.

Source: Hacker News

Source: Hacker News

Response and Mitigation Efforts

Microsoft has shared its findings with OpenAI, which subsequently identified and disabled the API key and associated account believed to have been used by the attackers

2

. The company emphasized that this threat "does not represent a vulnerability or misconfiguration, but rather a way to misuse built-in capabilities of the OpenAI Assistants API"

3

.

To help security teams identify similar threats, Microsoft has published hunting queries designed to spot unusual connections to OpenAI endpoints by process name, providing an early detection method for distinguishing legitimate chatbot activity from malicious use

1

.

The researchers have also provided comprehensive mitigation recommendations, including frequent auditing of firewalls and web server logs, and reviewing perimeter firewall and proxy settings to limit unauthorized access to services

3

.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo