Hackers have found a new use for OpenAI's Assistants API – not to write poems or code, but to secretly control malware. Microsoft this week detailed a previously unseen backdoor dubbed "SesameOp," which abuses OpenAI's Assistants API as a command-and-control channel to relay instructions between infected systems and the attackers pulling the strings. First spotted in July during a months-long intrusion, the campaign hid in plain sight by blending its network chatter with legitimate AI traffic – an ingenious way to stay invisible to anyone assuming "api.openai.com" meant business as usual. According to Microsoft's Incident Response team, the attack chain starts with a loader that uses a trick known as ".NET AppDomainManager injection" to plant the backdoor. The malware doesn't talk to ChatGPT or do anything remotely conversational; it simply hijacks OpenAI's infrastructure as a data courier. Commands come in, results go out, all via the same channels millions of users rely on every day. By piggy-backing on a legitimate cloud service, SesameOp avoids the usual giveaways: no sketchy domains, no dodgy IPs, and no obvious C2 infrastructure to block. "Instead of relying on more traditional methods, the threat actor behind this backdoor abuses OpenAI as a C2 channel as a way to stealthily communicate and orchestrate malicious activities within the compromised environment," Microsoft said. "This threat does not represent a vulnerability or misconfiguration, but rather a way to misuse...
OpenAI API moonlights as malware HQ in Microsoft’s latest discovery
The Register
·Carly Page
·Published Nov 4, 2025
·Updated
Affected Software
2 affected components
OpenAI Assistants API
Microsoft SesameOp
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the misuse of OpenAI's Assistants API to control malware, specifically a backdoor named 'SesameOp.'
2
What security implications are discussed?
The article highlights the risk of APIs being exploited by hackers to facilitate unauthorized access and control over malware.
3
What products or software are affected?
The affected software includes OpenAI's Assistants API and Microsoft's SesameOp malware.
4
Who discovered the vulnerabilities related to the API misuse?
Microsoft discovered the vulnerabilities linked to the misuse of OpenAI's Assistants API.
5
What is SesameOp in the context of this article?
SesameOp is a previously unseen backdoor that exploits the OpenAI Assistants API for malicious purposes.