Story perspectives
Microsoft Discovers Covert OpenAI API Exploit by SesameOp
11/4/2025
30 7
1 of 1
Story summary
- SesameOp exploits OpenAI's Assistants API as a covert command-and-control channel, discovered by Microsoft's Incident Response team in July 2025.
- The backdoor relays commands and steals data while masquerading as legitimate traffic.
- It uses a loader and a backdoor module, with .NET AppDomainManager injection to evade detection.
- OpenAI and Microsoft disabled the compromised API key, and they confirmed the malicious account did not access broader AI services.
