Malicious SesameOp Netapi64 Loader DLL Load via Masqueraded Netapi Module (via image_load)

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-07-30
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects loading of Netapi64.dll, a loader module used by the SesameOp backdoor that masquerades as a legitimate Windows networking library while relaying commands through the OpenAI Assistants API for command and control. Adversaries use this .NET loader to decrypt and execute payloads under a trusted-looking name, so catching the module load exposes the implant before its covert C2 channel activates.

Related detections9 linkedT1071.001 — drag to rearrange
Possible Remcos C2 Connection from eilowutil Process
Possible MOVEit Transfer SSRF via MOVEitISAPI action m2
Malicious Non-Interactive Encoded PowerShell Stager (via process_creation)
Suspicious Tomcat Campaign Command and Control Domain Resolution (via dns_query)
Suspicious TeamTNT Command and Control Domain Resolution (via dns_query)
Malicious CastleLoader C2 Communication via Hardcoded User-Agent
Suspicious Hidden PowerShell Executing Substring of Dropped File
Suspicious Outbound Connection From CasPol Binary
PowerShell Encoded or Download-Cradle Command Line (via process_creation)
Malicious SesameOp Netapi64 Loader DLL Load via Masqueraded Netapi Module (via image_load)
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.