logo

Russian Hacker Used Jailbroken Gemini to Steal Crypto Wallets

ID: 1a909ac2-ea6a-50ad-a628-c5b6bd9cdcfd

STIX ID: report--1a909ac2-ea6a-50ad-a628-c5b6bd9cdcfd

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Lucas Martin

...
...

**Executive summary:** TrendAIā„¢ Research exposed a five-year fraud campaign by a Russian-speaking solo operator leveraging a persistently jailbroken Google Gemini to automate targeted credential stuffing, WordPress administrator account compromises, and distribution of a trojanized cryptocurrency wallet (StellarMonSetup.exe / GoToResolve RAT), draining wallets and harvesting mnemonics; the report includes IOCs (IP, domains, hashes), operational TTPs (API key reuse, CLI-driven memory persistence, proxies, round-robin key rotation), affected victim sectors, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.