3 Sources
[1]
Microsoft: OpenAI API moonlights as malware HQ
Redmond uncovers SesameOp, a backdoor hiding its tracks by using OpenAI's Assistants API as a command channel Hackers have found a new use for OpenAI's Assistants API - not to write poems or code, but to secretly control malware. Microsoft this week detailed a previously unseen backdoor dubbed
[2]
Microsoft Detects "SesameOp" Backdoor Using OpenAI's API as a Stealth Command Channel
Microsoft has disclosed details of a novel backdoor dubbed SesameOp that uses OpenAI Assistants Application Programming Interface (API) for command-and-control (C2) communications. "Instead of relying on more traditional methods, the threat actor behind this backdoor abuses OpenAI as a C2 channel
[3]
Microsoft: A key OpenAI API is being used for 'espionage' by bad actors
On Monday, Microsoft Detection and Response Team (DART) researchers warned that an OpenAI API was being abused as a backdoor for malware. The researchers concluded that bad actors were using the novel backdoor to conduct long-term espionage operations. Specifically, Microsoft's cybersecurity
Share
Copy Link
Microsoft's cybersecurity team discovered a sophisticated backdoor called SesameOp that abuses OpenAI's Assistants API as a command-and-control channel. The malware hides malicious activities by blending with legitimate AI traffic, enabling long-term espionage operations while evading traditional detection methods.
Microsoft's Detection and Response Team (DART) has uncovered a sophisticated backdoor operation that represents a concerning evolution in cybercriminal tactics. The malware, dubbed SesameOp, was first detected in July 2025 during an investigation into what Microsoft described as a "sophisticated security incident" where unknown threat actors had maintained persistence within a target environment for several months
1
2
.
Source: Mashable
What makes SesameOp particularly noteworthy is its innovative approach to command-and-control communications. Rather than establishing traditional malicious infrastructure that security teams typically monitor, the backdoor exploits OpenAI's Assistants API as a covert communication channel
3
.The SesameOp backdoor operates through a sophisticated multi-component system designed for maximum stealth and persistence. The malware consists of a loader component called "Netapi64.dll" and a .NET-based backdoor named "OpenAIAgent.Netapi64" that leverages the OpenAI API for command-and-control operations
2
.
Source: The Register
The attack chain begins with a technique known as ".NET AppDomainManager injection," which allows the malware to plant itself within legitimate processes. The DLL component is heavily obfuscated using Eazfuscator.NET and is loaded at runtime through this injection method, making detection significantly more challenging
1
.Once operational, the backdoor fetches encrypted commands from OpenAI's Assistants API, decrypts and executes them locally, then posts the results back through the same channel. This creates what Microsoft describes as a "complex arrangement" of internal web shells designed to execute commands relayed from persistent, strategically placed malicious processes
2
.The genius of SesameOp lies in its ability to hide in plain sight. By piggy-backing on OpenAI's legitimate cloud infrastructure, the malware avoids traditional detection methods that look for suspicious domains, questionable IP addresses, or obvious command-and-control infrastructure. Network traffic to "api.openai.com" appears entirely normal to security monitoring systems
1
.Microsoft's analysis reveals that the implant uses payload compression and layered encryption to further obscure commands and exfiltrated data. The malware doesn't interact with ChatGPT or perform any conversational AI functions; instead, it simply hijacks OpenAI's infrastructure as a data courier, blending malicious communications with the millions of legitimate API calls made daily
1
.
Source: Hacker News
Related Stories
Microsoft has shared its findings with OpenAI, which subsequently identified and disabled the API key and associated account believed to have been used by the attackers
2
. The company emphasized that this threat "does not represent a vulnerability or misconfiguration, but rather a way to misuse built-in capabilities of the OpenAI Assistants API"3
.To help security teams identify similar threats, Microsoft has published hunting queries designed to spot unusual connections to OpenAI endpoints by process name, providing an early detection method for distinguishing legitimate chatbot activity from malicious use
1
.The researchers have also provided comprehensive mitigation recommendations, including frequent auditing of firewalls and web server logs, and reviewing perimeter firewall and proxy settings to limit unauthorized access to services
3
.Summarized by
Navi
[1]
[2]
27 Jul 2026•Technology

19 Feb 2026•Technology

09 Sept 2026•Technology

1
Policy and Regulation

2
Technology

3
Policy and Regulation
