Microsoft Detects “SesameOp” Backdoor Using OpenAI’s API as a Stealth Command Channel
Microsoft has revealed information on a new backdoor called SesameOp that communicates command-and-control (C2) via the OpenAI Assistants Application Programming Interface (API).
The Detection and Response Team (DART) at Microsoft Incident Response stated in a technical report released Monday that the threat actor responsible for this backdoor uses OpenAI as a C2 channel to covertly communicate and plan malicious actions within the compromised environment, rather than depending on more conventional techniques.
This is accomplished by a backdoor component that uses the OpenAI Assistants API as a relay or storage mechanism to retrieve commands, which the virus subsequently executes.
According to the IT giant, the implant was found in July 2025 as part of a complex security event wh...

