Stolen Gemini API Keys Fuel Automated Telegram Influence Campaign
ID: 2d401e78-3b75-5762-840e-d88390bd7b73
STIX ID: report--2d401e78-3b75-5762-840e-d88390bd7b73
Feed Name: GBHackers
## Executive summary A Russian-speaking threat actor operating the Telegram channel “American Patriot” (≈17,000 subscribers) ran a multi-year fraud and influence campaign leveraging 73 stolen Google Gemini API keys and a jailbroken Gemini model to automate propaganda, credential theft, infrastructure management, and monetization. The actor deployed a trojanized cryptocurrency wallet (“StellarMonster”), combined infostealer logs with AI-generated password mutation to crack WordPress accounts across multiple sectors, compromised 29 WordPress admin accounts and one enterprise, and drained at least one crypto wallet—demonstrating how frontier AI and stolen credentials lower the barrier for complex cybercrime operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
