SesameOp Backdoor Uses OpenAI API for Covert C2 Communications

The SesameOp backdoor represents a sophisticated evolution in cyberattack methodologies by leveraging the OpenAI API to conduct covert command and control (C2) communications. This novel technique allows attackers to mask their malicious traffic within legitimate API calls, complicating detection efforts by traditional security systems. The backdoor's use of AI-driven platforms highlights the increasing intersection of artificial intelligence and cyber threats, signaling a new era of advanced persistent threats (APTs) that exploit cutting-edge technologies for stealth and persistence. Security researchers have identified that SesameOp's communication with its C2 servers via the OpenAI API enables encrypted and obfuscated data exchanges, making network monitoring and anomaly detection significantly more challenging. This approach not only evades conventional network defenses but also leverages the trust and widespread use of AI services to blend malicious activities into normal traffic patterns. Organizations are urged to update their threat detection frameworks to include monitoring of AI API usage patterns and to employ advanced behavioral analytics capable of identifying subtle deviations indicative of backdoor operations. The emergence of SesameOp underscores the critical need for cybersecurity teams to adapt to the evolving threat landscape where AI technologies are weaponized by threat actors. In conclusion, the SesameOp backdoor's innovative use of the OpenAI API for covert C2 communication exemplifies the dynamic nature of cyber threats and the importance of proactive defense strategies. Enhanced vigilance, continuous threat intelligence sharing, and integration of AI-aware security solutions are essential to mitigate risks posed by such advanced malware.

This Cyber News was published on www.darkreading.com. Publication date: Tue, 04 Nov 2025 14:55:07 +0000


Cyber News related to SesameOp Backdoor Uses OpenAI API for Covert C2 Communications

SesameOp Backdoor Uses OpenAI API for Covert C2 Communications - The SesameOp backdoor represents a sophisticated evolution in cyberattack methodologies by leveraging the OpenAI API to conduct covert command and control (C2) communications. This novel technique allows attackers to mask their malicious traffic ...
1 week ago Darkreading.com
Sam Altman's Return As OpenAI CEO Is A Relief-and Lesson-For Us All - The sudden ousting of OpenAI CEO Sam Altman on Friday initially seemed to suggest one thing: he must have done something really, really bad. Possibly illegal. So when OpenAI's board of directors publicly announced that Altman was fired after "Failing ...
1 year ago Forbes.com
OpenAI Assistants API Exploited by SesameOp Malware for Stealthy Attacks - The recent discovery of the SesameOp malware exploiting the OpenAI Assistants API marks a significant development in cyber threats. This sophisticated malware leverages AI capabilities to conduct stealthy and evasive attacks, posing new challenges ...
1 week ago Infosecurity-magazine.com
Microsoft Invests Billions in OpenAI – Innovator in Chatbot and GPT Technology - Microsoft has announced a $1 billion investment in OpenAI, the San Francisco-based artificial intelligence (AI) research and development firm. Founded by tech moguls Elon Musk and Sam Altman, OpenAI is a leader in AI technology, and the investment ...
2 years ago Securityweek.com
OpenAI's board might have been dysfunctional-but they made the right choice. Their defeat shows that in the battle between AI profits and ethics, it's no contest - The drama around OpenAI, its board, and Sam Altman has been a fascinating story that raises a number of ethical leadership issues. What are the responsibilities that OpenAI's board, Sam Altman, and Microsoft held during these quickly moving events? ...
1 year ago Fortune.com Equation
OpenAI is to Launch a AI Web Browser in Coming Weeks - The new browser will feature integrated AI agent capabilities designed to autonomously handle various online tasks, positioning OpenAI as a direct competitor to traditional browser giants like Google Chrome while advancing the company’s vision ...
4 months ago Cybersecuritynews.com
Defining Good: A Strategic Approach to API Risk Reduction - A good API security strategy starts with a well thought out API security posture governance program that spans from design to deployment. That standard, if communicated and enforced effectively, will not only positively affect how a developer designs ...
1 year ago Securityboulevard.com
UK Scrutiny Of Microsoft Partnership With OpenAI - CMA seeks feedback about the relationship between Microsoft and OpenAI, and whether it has antitrust implications. Microsoft, it should be remembered, was firmly rebuked for its conduct by the CMA in October after the UK regulator reversed its ...
1 year ago Silicon.co.uk
BianLian GOs for PowerShell After TeamCity Exploitation - In conjunction with GuidePoint's DFIR team, we responded to an incident that began with the exploitation of a TeamCity server which resulted in the deployment of a PowerShell implementation of BianLian's GO backdoor. The threat actor identified a ...
1 year ago Securityboulevard.com CVE-2024-27198 CVE-2023-42793 BianLian
OpenAI's Sora Generates Photorealistic Videos - OpenAI released on Feb. 15 an impressive new text-to-video model called Sora that can create photorealistic or cartoony moving images from natural language text prompts. Sora isn't available to the public yet; instead, OpenAI released Sora to red ...
1 year ago Techrepublic.com
Microsoft SesameOp malware abuses OpenAI assistants API in attacks - Microsoft has identified a new malware strain named SesameOp that exploits the OpenAI Assistants API to enhance its attack capabilities. This innovative malware leverages AI-driven functionalities to automate and improve the efficiency of its ...
1 week ago Bleepingcomputer.com
Salt Security Delivers API Posture Governance Engine - PRESS RELEASE. PALO ALTO, Calif., Jan. 17, 2024 /PRNewswire/ - Salt Security, the leading API security company, today announced multiple advancements in discovery, posture management and AI-based threat protection to the industry leading Salt ...
1 year ago Darkreading.com
Imperva Named an Overall Leader in the KuppingerCole Leadership Compass: API Security and Management Report - We're thrilled to share that Imperva has achieved the prestigious status of Overall Leader in the KuppingerCole Leadership Compass: API Security and Management report. A notable achievement is being recognized as one of the few non-gateway-first ...
1 year ago Imperva.com
ChatGPT Maker OpenAI Raises $6.6bn In Funding | Silicon UK - Last week when OpenAI’s ‘for profit’ restructuring move was revealed, three senior executives abruptly announced they were departing, including Chief Technology Officer Mira Murati, VP Research Barret Zoph, and Chief Research ...
1 year ago Silicon.co.uk
That time I broke into an API and became a billionaire - This included an internal API with a dependency on a third-party banking API. We'll get to the banking API later in this story. That's all thanks to developers embracing agile development, microservices, and API gateway redirection that exposed ...
1 year ago Securityboulevard.com
OpenAI Launches Security Committee Amid Ongoing Criticism - The new committee comes in the wake of two key members of the Superalignment team - OpenAI co-founder Ilya Sutskever and AI researcher Jan Leike - left the company. The shutting down of the superalignment team and the departure of Sutskever and Leike ...
1 year ago Securityboulevard.com
Nadella Says Microsoft 'Comfortable' With OpenAI Governance - Microsoft chief Nadella says he is 'comfortable' with OpenAI's non-profit governance structure, plays down competition issues. Microsoft secured a non-voting board observer role at OpenAI following Altman's firing and return, but Nadella said ...
1 year ago Silicon.co.uk
Leak confirms OpenAI's GPT 4.1 is coming before GPT 5.0 - As spotted by AI researcher Tibor Blaho, OpenAI is already testing model art for o3, o4-mini, and GPT-4.1 (including nano and mini variants) on the OpenAI API platform. Also, GPT-5 isn't happening anytime soon, as OpenAI plans to focus on o3, ...
7 months ago Bleepingcomputer.com
Unified API Protection - A massive segment of organizations' digital footprint today is built around internal and external APIs. As more IT leaders realize and acknowledge the size of APIs' influence, it's become clear that new methods are needed to secure those APIs. While ...
2 years ago Cequence.ai
OpenAI Reveals ChatGPT Is Being DDoS-ed - ChatGPT developer OpenAI has admitted the cause of intermittent outages across its flagship generative AI offering over the past day: distributed denial of service attacks. According to the developer's status page, ChatGPT and its API have been ...
1 year ago Infosecurity-magazine.com
What do CISOs need to know about API security in 2024? - According to Postman's 2023 State of the API Report, roughly 66% of participants indicated that their APIs contribute to generating revenue. A recent ESG survey on API security showed that 92% of organisations using APIs have experienced a breach in ...
1 year ago Cybersecurity-insiders.com
OpenAI Offering Up to $100,000 for Critical Vulnerabilities in its Infrastructure - This substantial bounty increase signals OpenAI’s recognition that as its AI systems become more powerful and widely deployed, the security stakes continue to rise, requiring proportionally stronger investments in identifying and addressing ...
7 months ago Cybersecuritynews.com
Russian Sandworm Group Using Novel Backdoor to Target Ukraine - Russian nation-state group Sandworm is believed to be utilizing a novel backdoor to target organizations in Ukraine and other Eastern and Central European countries, according to WithSecure researchers. The previously unreported backdoor, dubbed ...
1 year ago Infosecurity-magazine.com

Cyber Trends (last 7 days)