Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SesameOp Malware Abuses OpenAI API 

SesameOp Malware Abuses OpenAI API 

Posted on November 4, 2025November 4, 2025 By CWS

A risk actor has abused the OpenAI Assistants API as a communication mechanism between its command-and-control (C&C) server and a stealthy backdoor, Microsoft studies.

Dubbed SesameOp, the backdoor was deployed as a part of a complicated assault wherein the risk actor maintained entry to the compromised setting for months, counting on a posh community of net shells for command execution.

The instructions, Microsoft says, have been relayed by way of malicious processes that abused compromised Visible Studio utilities to load malicious libraries, a method known as .NET AppDomainManager injection.

Enabling the attackers to handle contaminated gadgets remotely, SesameOp was designed for long-term persistence, suggesting the assault was geared toward espionage.

The attackers, Microsoft explains, modified the configuration file of a number executable so it could load at runtime a DLL named Netapi64.dll, utilizing .NET AppDomainManager injection.

The DLL acts as a loader for the backdoor, which is saved within the Temp folder beneath the title OpenAIAgent.Netapi64.

The malware makes use of the OpenAI Assistants API to fetch instructions from its C&C server and, as soon as the duty has been accomplished, it sends the consequence to OpenAI, as a message.

The OpenAI Assistants characteristic allows the creation of customized AI brokers that customers can affiliate with duties, workflows, and domains.Commercial. Scroll to proceed studying.

When establishing communication, the backdoor first queries a vector retailer listing from OpenAI, and checks if it incorporates hostnames. No hostname ought to exist if the communication takes place for the primary time, and a vector retailer is created utilizing the contaminated system’s hostname.

Subsequent, the backdoor retrieves a listing of Assistants from the attacker’s OpenAI account. The listing contains ID, title, description, and directions variables.

The outline area might include the choices Sleep, Payload, or Consequence. The attackers use the primary two to ship messages and payloads to the backdoor, that are decoded and executed utilizing the instruction worth. The third is utilized by the malware to ship the consequence from the payload’s execution.

Microsoft says it recognized an API key used on this assault and notified OpenAI, which disabled each the important thing and the related account that was possible utilized by the risk actor as a part of the operation. The OpenAI Assistants API can be deprecated in August 2026.

Associated: Russian APT Switches to New Backdoor After Malware Uncovered by Researchers

Associated: China-Linked Hackers Hijack Net Site visitors to Ship Backdoor

Associated: Microsoft Dissects PipeMagic Modular Backdoor

Associated: MITRE Hackers’ Backdoor Has Focused Home windows for Years

Security Week News Tags:Abuses, API, Malware, OpenAI, SesameOp

Post navigation

Previous Post: Bugcrowd Acquires Application Security Firm Mayhem
Next Post: SesameOp Leveraging OpenAI Assistants API for Stealthy Communication with C2 Servers

Related Posts

Exploitation of Critical JFrog Artifactory Flaw Exploitation of Critical JFrog Artifactory Flaw Security Week News
OpenAI to Help DoD With Cyber Defense Under New 0 Million Contract OpenAI to Help DoD With Cyber Defense Under New $200 Million Contract Security Week News
Cylake Secures M Funding for On-Premises Cybersecurity Cylake Secures $45M Funding for On-Premises Cybersecurity Security Week News
White House Proposes 7 Million CISA Budget Cut White House Proposes $707 Million CISA Budget Cut Security Week News
HPE AOS-CX Flaw Allows Admin Password Resets HPE AOS-CX Flaw Allows Admin Password Resets Security Week News
Massive Azure CLI Password Spray Campaign Uncovered Massive Azure CLI Password Spray Campaign Uncovered Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark