OpenAI API Hijacked: The Sneaky SesameOp Malware Strikes!
Microsoft security researchers have stumbled upon a backdoor malware, SesameOp, that cleverly uses the OpenAI Assistants API as a covert command-and-control channel. It’s like the malware equivalent of whispering in your ear while pretending to be a helpful assistant.

Hot Take:
Who knew that AI Assistants could moonlight as secret agents? It turns out that while we were busy asking OpenAI to write our grocery lists, cybercriminals were using it to orchestrate clandestine operations. Looks like even Siri and Alexa need to start watching their backs.
Key Points:
- Microsoft discovered a new malware, SesameOp, using OpenAI’s API as a covert command-and-control channel.
- The malware facilitates persistent access and remote management of compromised devices.
- SesameOp uses OpenAI’s Assistants API for storing and relaying encrypted commands.
- Microsoft and OpenAI collaborated to identify and disable the malicious API account.
- Microsoft recommends several mitigation strategies to combat SesameOp attacks.
Already a member? Log in here
