logo

Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes

ID: b7fb9c69-4876-5939-8ebe-1a533edafc1f

STIX ID: report--b7fb9c69-4876-5939-8ebe-1a533edafc1f

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: Mayura Kathir

...
...

TrendAI analyzed March–April 2026 Gemini CLI session logs from a Russian-speaking actor dubbed “bandcampro” and found the operator used an AI coding agent to rebuild and migrate a lightweight HTTPS-based C2 for a small botnet (eight systems at a dental clinic, including OpenDental access). The AI performed architecture, code generation, deployment, troubleshooting (fixing 502 errors and Cloudflare issues), and operational recommendations, enabling the actor to restore control within minutes; the operation used PowerShell beacons, WMI/scheduled task/registry persistence, credential/WordPress attacks, and data-exfiltration/fraud planning, highlighting automation-driven resilience and the need for behavioral detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.