Malicious SesameOp Netapi64 Artifact Files Written to Windows Temp (via file_event)

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-07-30
Updated
2026-08-28

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of SesameOp working files such as Netapi64.start and Netapi64.Exception in Windows Temp along with files carrying the .Netapi64 extension. These artifacts are dropped by the SesameOp backdoor while it decrypts payloads and stores state for its OpenAI Assistants API C2 relay. Surfacing these distinctive on-disk markers reveals an active backdoor foothold that hides its traffic inside a legitimate cloud API.

Related detections9 linkedT1140 — drag to rearrange
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Hidden PowerShell Archive Extraction via ExtractToDirectory
Malicious Shell Payload Piped from curl to zsh
CastleLoader ClickFix PowerShell Hex Decode and Re-Execution
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Suspicious tar Extraction of Staged Archive to Temp (via process_creation)
Malicious Multi Layer Base64 Decoded Payload Execution via Bash (via process_creation)
Malicious Certutil Decode of Encoded Web Shell to ASPX (via process_creation)
Malicious SesameOp Netapi64 Artifact Files Written to Windows Temp (via file_event)
Pivot detection · T1140 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.